> For the complete documentation index, see [llms.txt](https://purplebyteone.gitbook.io/index/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://purplebyteone.gitbook.io/index/notes/education/base/purple-team/comptia/courses/security/security+/chapter-1.md).

# Chapter 1

## Managing Risk

* As an administrator, you are responsible
* You must enable data to exist
* You must protect it, authenticate it, secure it, and keep it in the form that complies with every applicable law, policy, and regulation.
* Data can be accidentally deleted, overwritten, stolen, and lost.
* Potential harms represent risks
* Data can be corrupted, it can be accessed by those who shouldn’t see it, values can be changed

{% hint style="danger" %}
If the cost of preventing a particular risk from becoming a reality exceeds the value of the harm that could occur, then a cost-benefit risk calculation dictates that the risk should stand
{% endhint %}

* Risk calculations weigh a potential threat against the likelihood or probability of it occurring.
* Residual risk - fact that some risks will and must remain
