Question: Answer this question based on The Security Risk Assessment Handbook by DOUGLAS J . LANDOLL Exercises Section 1 0 . 2 mentions solution sets as
Answer this question based on The Security Risk Assessment Handbook by DOUGLAS JLANDOLL
Exercises
Section mentions solution sets as the application of several safeguards to address a single vulnerability or a set of closely related vulnerabilities. Give an example of a solution set for the following vulnerabilities:
a Front entrance is susceptible to piggybacking.
b Inhousedeveloped Web applications are susceptible to SQL injection attacks.
c Critical patches are not applied within days.
d USB thumb drives containing sensitive data are lost outside of the
building.
Estimate quantitatively the cost of implementing the following controls:
a Secure code development training for developers
b Fire suppression system for sq ft cu ft data center
c Wholedisk encryption for laptops
Estimate the costs for the same controls above using the following qualitative
scale:
Consider the safeguards described in
a Suggest a quantitative measurement approach for effectiveness of
b What would it cost to obtain that measurement?
c Is it worthwhile to do so
Estimate the effectiveness of using the qualitative scale of High, Medium, and Low.
a Using only the qualitative measurements for cost and effectiveness, what
controls would you suggest be implemented?
b Is it likely that quantitative methods would produce different results?
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
