Threats and Vulnerabilities Flashcards
Threats and Vulnerabilities
A weakness inherent in an asset that leaves it open to a threat
Vulnerability
Threats and Vulnerabilities
An attack (exploit) that a malicious actor will use against an asset
Threat
Threats and Vulnerabilities
Individuals or orgs who perpetrate attacks against vulnerabilities
ie: script kiddies
Threat Actors
Threats and Vulnerabilities
Pathways to gain access to infrastructure
weak configs
open firewall ports
lack of user security awareness
lack of mfa
missing patches
ie - Equifax hack
infected USB thumb drives
Stuxnet work
Attack vectors
Threats and Vulnerabilities
Attack Vectors against
- manufacturers
- contractors
- implementers
- outsourced s/w development
Right-to-audit clause
Supply-chain attack
Threats and Vulnerabilities
Takes advantage of a vulnerability
Exploits
Threats and Vulnerabilities
Sources of threats
Threat actors
Threats and Vulnerabilities
Pathways to gain access to restricted systems
Attack vectors