03. Vulnerability and Control Deficiency Analysis Flashcards
Vulnerability and Control Deficiency Analysis
Any weakness in a system that permits an attacker to compromise a target process or system successfully
Vulnerability
- not the attack vector or technique
142
Vulnerability and Control Deficiency Analysis
The attack vector or technique that could be used to exploit a vulnerability
Threat
143
Vulnerability and Control Deficiency Analysis
Vulnerabilities usually take one of the following forms
- Configuration fault
- Design fault
- Known unpatched weakness
- Undisclosed unpatched weakness
- Undiscovered weakness
143
Vulnerability and Control Deficiency Analysis
Vulnerabilities exist everwhere. Security managers should consider that every component of every type system has both known and unknown vulnerabilities. Common places where vulnerabilities exist
- Network Devices
- Operating systems
- Database Management Systems
- Software Applications
- Physical Security
- Business Processes
- Personnel
144
Third Party Vulnerability Identification
Organisations typically outsource at least part of their Software or IT operation. Organisations fail to thoroughly understand the…
Security Responsibility Model
- Fail to understand which poritions of security are their responsibility and which are managed
144