Information Security Risk Management
Fall Semester 2015
Instructions:
All responses and citations must be APA compliant.
Attempt to provide complete and correct answers to the questions. While preparing the answers do not copy directly from the textbook. Use your own words in complete sentences and organize appropriately. Poorly written answers will reduce the clarity of your answer and may result in a failing grade.
All the best!
Answer ALL questions (100 points).
1. Define POAM and its use in an Organization. (15 points)
2. Describe the main components of a good password policy. Why is it important to establish a password expiration policy? (15 points)
3. What is the relationship between a Disaster Recovery Plan and a Business Continuity Plan? (15 points)
4. Compare and contrast Total Risk and Residual Risk. Why is residual risk important and who is accountable for it? (15 points)
5. Define the four risk management techniques and provide a scenario that illustrates each technique (40 points). This question you can use citations and references for supporting scholarly sources.