|
Relationship |
Profile |
|
O pportunity |
|
Frequency |
Impacts |
Effective Safeguards |
Proven |
Mandated |
|
Insiders :(In-laws?) |
Clueless |
None |
Access & |
Error & |
High |
Low-Med |
|||
|
|
Contractor |
Varies |
Weak |
Exploits Lax |
Unknown |
Med-High |
|||
|
|
Disgruntled |
Get Even |
Insider |
Exploits Lax |
Low-Med |
High |
|||
|
|
Gamers |
Have Fun |
After Hours |
Compromises |
Low |
Med-High |
|||
|
Outsiders :(Outlaws?) |
Script |
Intellectual |
Spare Time |
Freeware |
High |
Low-Med |
|||
|
|
Hacktivist |
Political |
See |
Various |
Unknown |
Med-High |
|||
|
|
Coder / Pro |
Peer |
Lax Software |
Discovers |
Low |
High (Day Zero) |
|||
|
|
Comp Intel & Economic Espionage |
Economic |
Medium |
High |
|||||
|
|
State-Sponsored |
Economic |
Unknown
|
High |
|||||
©
2001 by ACCTTS, LLC. All Rights Reserved Worldwide.IE Only Ref:
http://my.octopus.com/view.oce?v=6B3937A27CD749E39C510BCF93ED8934 [ACCTTS-SIRT Selection Support PKM]
|
Operational Risk Factors: |
Type Digital |
Outage |
Outage |
Time- Critical |
Outage |
Protection Policy Pre-Reqs |
Defined SIRT Roles |
Key |
Desired Metrics? |
|
|
Anti-Social |
||||||||
|
|
Deletion (Accidental) |
||||||||
|
|
Denial of Service |
||||||||
|
Destruction |
|||||||||
|
Errors & |
|||||||||
|
Unauthorized Access |
|||||||||
|
Unauthorized Disclosure |
|||||||||
|
Unauthorized |
|||||||||
|
Unauthorized |
|||||||||
|
Network Abuse |
|||||||||
©
2001 by ACCTTS, LLC. All Rights Reserved Worldwide.Gartner Group: Information Systems Security Dimensions
|
Requirement |
Definitions ( Via DISA: ISO/IEC 7498-2) |
Safeguard Technique |
|
Non-Interference |
Ensure that control is exercised over the entry and use |
|
|
Authentication |
Ensure that users and/or applications are uniquely identified |
|
|
Authorization |
Ensure that a correctly authenticated user can access only |
|
|
Confidentiality |
Ensure that only those people who have a need |
|
|
Integrity |
Ensure that it can be identified if a transaction has changed |
|
Gartner Group: Information Systems Security Dimensions
|
Requirement |
Definitions ( Via DISA: ISO/IEC 7498-2) |
Safeguard Technique |
|
Privacy |
Ensure that information provided by employees, customers and others is protected such that it is used solely for the stated purposes of the enterprise, the person authorised such use and the enterprise is |
|
|
Nonrepudiation |
Ensure that both the sender and receiver of information can unequivocally prove that the exchange occurred |
|
|
Availability |
Ensure that the enterprise has suitable recoverability and protection from system failures, natural disasters or malicious attacks. |
|
|
Source: |
http://mdev.temple.edu/gartner/research/ras/98600/98601/98601.html | ACCTTSalus-M_O_Matrix.htm |