Threats and Vulnerabilities Flashcards
Vulnerability
Percentage of threat events that will become loss events.
Calculate vulnerability
Threat capability vs. resistance strength
Percentage of threat events that become loss events.
Percentage of 1’s vs. 0’s.
Threat capability continuum
Range of percentiles from 0-100 that threat communities are placed.
When are we vulnerable in the capability continuum.
Any time the threat capability exceeds the resistance strength.
(Right of the line)
What is the value for vulnerability if the resistance strength is greater than the threat capability?
0
What is the value for vulnerability if the threat capability is greater than the resistance strength?
1
How is loss event frequency determined?
Vulnerability vs. threat event frequency
Is it best to start at the top or bottom of the FAIR model?
Top
Threat event frequency x Vulnerability =
Loss Event Frequency
Threat profiling
Profile of methods, motivations, resources.
Helps to identify threat communities.
What does this question identify?
“who or what is capable of acting against my asset in a way that could cause loss?”
A threat