Question: If an organization has three information assets to evaluate for risk management as shown in the accompanying data, which vulnerability should be evaluated for additional

  1. If an organization has three information assets to evaluate for risk management as shown in the accompanying data, which vulnerability should be evaluated for additional controls first? Which one should be evaluated last?

An evaluation of the provided asset vulnerabilities results in:

Asset A:

This is a switch that has two vulnerabilities. The first involves a hardware failure likelihood of 2 and the second involves a buffer attack likelihood of 1. The switch has an impact rating of 4.

Asset B:

This is a web server that deals with e-commerce transactions. It has one vulnerability with a likelihood of 1. However it has an impact rating of 5.

Asset C:

This is a control console with no password protection with a likelihood of attack of 1. It has no controls and an impact rating of 1.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!