Analysis Scoping Flashcards
How can assumptions be managed?
Clearly defining and scoping an analysis.
What is Analysis Scoping?
Clearly defining the scenario we wish to measure.
Key asset example
Data on a lost laptop
Threat vector
A method or approach (hacking, etc.)
Threat event types (4)
Malicious
Error
Failure
Natural
Threat Profiling
Describing threat communities based on consistent profiles.
Risk Triad
Assets Threats Effects = Loss Event
Loss types
Confidentiality
Integrity
Availability
Parts needed to define a scenario…
Asset
Threat
Effect
Single sentence (Determine how much risk is associated with…)
Scenario parsing
Breaking a scenario into multiple analyses. (Or combining scenarios)
Fair is a risk _____ framework.
Fair is a risk analysis framework.