If an organization must evaluate the following three information assets for risk management, which vulnerability should be evaluated first for additional controls? Which should be evaluated last?
• Switch L4 7 connects a network to the Internet. It has two vulnerabilities: it is susceptible to hardware failure at a likelihood of 0.2, and it is subject to an SNMP buffer overflow attack at a likelihood of 0.1. This switch has an impact rating of 90 and has no current controls in place. You are 75 percent certain of the assumptions and data.
• Server WebSrv6 hosts a company Web site and performs e-commerce transactions. It has a Web server version that can be attacked by sending it invalid Unicode values. The likelihood of that attack is estimated at 0.1. The server has been assigned an impact value of 100, and a control has been implanted that reduces the impact of the vulnerability by 75 percent. You are 80 percent certain of the assumptions and data.
• Operators use an MGMT45 control console to monitor operations in the server room. It has no passwords and is susceptible to unlogged misuse by the operators. Estimates show the likelihood of misuse is 0.1. There are no controls in place on this asset; it has an impact rating of 5. You are 90 percent certain of the assumptions and data.
Fundamentals of Information Systems
Database Systems: Design, Implementation, & Management
Fundamentals of Information Systems
A Guide to SQL
Database Systems: Design, Implementation, & Management
Principles of Information Systems (MindTap Course List)
Fundamentals of Geotechnical Engineering (MindTap Course List)
Precision Machining Technology (MindTap Course List)
Cornerstones of Financial Accounting
Engineering Fundamentals: An Introduction to Engineering (MindTap Course List)
Automotive Technology: A Systems Approach (MindTap Course List)
Mechanics of Materials (MindTap Course List)
Management Of Information Security
Systems Analysis and Design (Shelly Cashman Series) (MindTap Course List)
EBK ELECTRICAL WIRING RESIDENTIAL
Solid Waste Engineering
International Edition---engineering Mechanics: Statics, 4th Edition
Electric Motor Control
Principles of Geotechnical Engineering (MindTap Course List)
Fundamentals of Chemical Engineering Thermodynamics (MindTap Course List)
Automotive Technology
Steel Design (Activate Learning with these NEW titles from Engineering!)
Enhanced Discovering Computers 2017 (Shelly Cashman Series) (MindTap Course List)
Structural Analysis
Network+ Guide to Networks (MindTap Course List)
Welding: Principles and Applications (MindTap Course List)
A+ Guide to Hardware (Standalone Book) (MindTap Course List)
Principles of Information Systems (MindTap Course List)