官术网_书友最值得收藏!

Step 6 – rate the threats

Evaluating the likelihood and impact of each of the previous threats allows for selecting appropriate types and levels of control (and their related costs) to mitigate each. Threats with higher risk ratings may require larger amounts of investment to mitigate. Conventional threat-rating methodologies can be used at this step, including Microsoft's DREAD approach.

The DREAD model asks basic questions for each level of risk and then assigns a score (1 to 10) for each type of risk that emerges from a particular threat:

  • Damage: This is the amount of damage incurred by a successful attack
  • Reproducibility: What level of difficulty is involved in reproducing the attack?
  • Exploitability: Can the attack be easily exploited by others?
  • Affected users: What percentage of a user/stakeholder population would be affected given a successful attack?
  • Discoverability: Can the attack be discovered easily by an attacker?

An example of a threat rating for our smart parking system is provided in the following table:

Security architects who are responsible for designing the security controls for an IoT system should continue with this exercise until all threats have been rated. Once complete, the next step is to perform a comparison of each against the others based on each one's threat rating (overall score). This will help prioritize the mitigations within the security architecture.

主站蜘蛛池模板: 彰化市| 龙井市| 多伦县| 遵义市| 浦北县| 广德县| 陈巴尔虎旗| 大安市| 武夷山市| 云霄县| 肥西县| 惠州市| 阿克陶县| 平陆县| 灵璧县| 沭阳县| 隆尧县| 松江区| 永安市| 西乡县| 黎川县| 洛南县| 涿鹿县| 房山区| 诸暨市| 长沙县| 贺州市| 五峰| 长白| 宁武县| 聂荣县| 五寨县| 保康县| 开封县| 公主岭市| 荃湾区| 隆尧县| 雅江县| 星子县| 泸定县| 施甸县|