Merkow - PPT - 02 F
Merkow - PPT - 02 F
Merkow - PPT - 02 F
Objectives
Objectives (cont.)
Introduction
Confidentiality
Integrity
Availability
Security
Goals
Integrity
Availabilit
y
Defense in depth
Functional requirements
Assurance requirements
10
11
12
Consequences/likelihood matrix
Likelihood
Consequences
1. Insignificant
2. Minor
3. Moderate
4. Major
5. Catastrophic
A (almost
certain)
High
High
Extreme
Extreme
Extreme
B (likely)
Moderate
High
High
Extreme
Extreme
C
(moderate)
Low
Moderate
High
Extreme
Extreme
D (unlikely)
Low
Low
Moderate
High
Extreme
E (rare)
Low
High
High
Pearson
2014, Information
LowEducation Moderate
Security: Principles and Practices, 2nd Edition
13
cont.
Vulnerability
Exploit
Attacker
14
15
16
17
People controls
Process controls
18
19
Summary
20