Week 2B - Vulnerabilities Flashcards
Vulnerabilities
Characteristics of, or weaknesses in a system that could be used to cause harm if acted on by a threat
What are the 3 main sources of vulnerabilities? (PPP)
- Property
- People
- Procedures
What are the 4 types of property?
Physical Assets
Hardware
Software
Data
Property - What considerations need to be made for Physical Assets?
Location of Information Assets
Physical Security Mechanisms
Maintenance
Monitoring and Logging
Property - What considerations need to be made for Hardware?
Reliability & Robustness: asset and supporting infrastructure
Redundancy
Property - What considerations need to be made for Software?
Source of Software: authorized, legitimate and supported
Downloading & Installing Processes
Design, Creation & Testing of Software
Need for Patches & Upgrades
Configuration/Misconfiguration
People - What considerations need to be made for Employees
Recruitment of Suitable staff
Monitoring of Access
Training for awareness and organisational processes
Processes - What considerations need to be made for Processes Used?
Access Control
Privilege Management
Backup of Files & Systems
Business Continuity Plans
Communication Processes
Staff Induction & Termination Processes