Writing assignment 7
You have just completed a qualitative threat assessment of the computer security of your organization, with the impacts and probabilities of occurrence listed in the table that follows. Properly place the threats in a 3-by-3 table similar to that in Figure 20.5. Which of the threats should you take action on, which should you monitor, and which ones may not need your immediate attention
|
Threat |
Impact |
Probability of Ocuurance |
|
Virus attack |
High |
high |
|
Internet Hacks |
Medium |
High |
|
Disgruntled employee hacks |
High |
Medium |
|
Weak Incidence Response Mechanism |
Medium |
Medium |
|
Theft of information By a trusted third-party contractor |
Low |
Medium |
|
Competitor hacks |
High |
Low |
|
Inadvertent release of noncritical information |
Low |
Low |
Figure 20.5:
Impact
|
High Low |
High Medium |
High High |
|
Medium Low |
Medium Medium |
Medium High |
|
Low Low |
Low Medium |
Low High |