Intro To Information Assurance & Security- Threats, Attacks, and Vulnerability Assessment
Rubric for week 1
System model 10% - Provide a scope description of the system you are assessing. Provide a network diagram of the system on which you are conducting a risk assessment.
Existing Countermeasures 10% - Describe the administrative, technical, and physical controls already in place to prevent, detect, and respond to threats.
Threat Agents and Possible Attacks 10% - Describe at least 12 possible threat agents and how attacks are accomplished with each (attention to attack paths)
Exploitable Vulnerabilities 10% - Describe at least 7 exploitable technical and physical vulnerabilities that would enable a successful attack.
Threat History and Business Impact 10% - List at least two security incidents that happened to this organization, or within its industry, against similar systems (same data or business process)
Risk and Contingencies Matrix 50% - Describe the risks associated with at least five threat/vulnerability sets defined in this document. Include recommendations for how to manage the risks.