官术网_书友最值得收藏!

Step 6 – rate the threats

Evaluating the likelihood and impact of each of the previous threats allows for selecting appropriate types and levels of control (and their related costs) to mitigate each. Threats with higher risk ratings may require larger amounts of investment to mitigate. Conventional threat-rating methodologies can be used at this step, including Microsoft's DREAD approach.

The DREAD model asks basic questions for each level of risk and then assigns a score (1 to 10) for each type of risk that emerges from a particular threat:

  • Damage: This is the amount of damage incurred by a successful attack
  • Reproducibility: What level of difficulty is involved in reproducing the attack?
  • Exploitability: Can the attack be easily exploited by others?
  • Affected users: What percentage of a user/stakeholder population would be affected given a successful attack?
  • Discoverability: Can the attack be discovered easily by an attacker?

An example of a threat rating for our smart parking system is provided in the following table:

Security architects who are responsible for designing the security controls for an IoT system should continue with this exercise until all threats have been rated. Once complete, the next step is to perform a comparison of each against the others based on each one's threat rating (overall score). This will help prioritize the mitigations within the security architecture.

主站蜘蛛池模板: 区。| 南城县| 奉贤区| 阆中市| 邹城市| 宝丰县| 海阳市| 衡水市| 城口县| 五大连池市| 通渭县| 平和县| 通州区| 潍坊市| 梓潼县| 木里| 铜山县| 齐齐哈尔市| 双牌县| 永胜县| 治多县| 昭苏县| 南雄市| 资兴市| 常德市| 龙口市| 蛟河市| 内丘县| 定边县| 信宜市| 乌兰察布市| 崇明县| 紫阳县| 肇庆市| 阿拉善左旗| 新晃| 汝南县| 凤庆县| 萝北县| 华坪县| 全南县|