Board index » Computer Armageddon: Help with whatever Computer or Security problem you're having » Security

 


Post new topic Reply to topic
Author Message
 Post subject: identifying the assets and their values
PostPosted: Tue Sep 12, 2006 11:39 pm
  

Just beginning to get the hang of it

Joined: Mon Jan 30, 2006 1:28 pm
Posts: 31
Hi

Apart from identifying the assets and their values,
the starting point for such a risk assessment is
what we call the threat agent: hurricanes, floods, fire,
virus, intruder, ..., (spammer, employee, ...)

Then, vulnerabilities for each threat agent are defined,
like thatched roof, lack of antivirus software, lack of entry-control, ...

As a result, you may define threats, like uncontrollable fire,
virus infection, stolen devices or 'secrets', ...


Then you continue with probabilities, impacts, countermeasures, ...
as you know it.


One source of confusion I have seen is the "difference"
between threat agents and threats. Often, these are
used as synonyms, which leads to confusion. At least from a
computer security perspective, a threat agents exploits a
vulnerability to realise a threat.

Good luck :)

Cheers

_________________
If the only tool you have is a hammer, you tend to see every problem as a nail.
(Abraham Maslow, Psychologist, 1908-70)


          Top  
 
 Post subject:
PostPosted: Wed Sep 13, 2006 8:48 am
  

User avatar
Frustrated Mad Scientist

Joined: Mon Jan 09, 2006 10:07 am
Posts: 7722
Location: Scotland
Cheers Sec, this stuff does my head in sometimes Image

_________________
"Man will never be free until the last king is strangled with the entrails of the last priest."
- Denis Diderot (1713-1784)


          Top  
 
 
Post new topic Reply to topic



Who is online

Users browsing this forum: No registered users and 0 guests


Display posts from previous:  Sort by  
Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum


cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group