Which vulnerability should be evaluated

Assignment Help Management Information Sys
Reference no: EM13756297

Management of information security


1. If an organization has three information assets to evaluate for risk management purposes as shown in the accompanying data, which vulnerability should be evaluated for additional controls first? Which vulnerability should be evaluated last?

Explain your reasons.

a. Switch L47 connects a network to the Internet. It has two vulnerabilities: (1)susceptibility to hardware failure with a likelihood of 0.2, (2) susceptibility to an SNMP buffer overflow attack with likelihood of 0.1. This switch has an impact rating of 90 and has no current controls in place. There is a 75 percent certainty of the assumption and data.

b. Server WebSrv6 hosts a company Web site and performs e-commerce transactions. It has Web server software that is vulnerable to attack via invalid Unicode values. The likelihood of such an attack is estimated at 0.1. The server has been assigned an impact value of 100, and a control has been implemented that reduces the impact of the vulnerability by 75 percent. There is an 80 percent certainty of the assumptions and data.

c. Operators use the MGMT45 control console to monitor operations in the server room. It has no passwords and is susceptible to unlogged misuse by the operators. Estimates show the likelihood of misuse is 0.1. There are no controls in place on this asset; which has an impact rating of 5. There is a 90 percent certainty of the assumptions and data.

Reference no: EM13756297

Questions Cloud

How does marketing mix help businesses create market segment : Describe the strategic marketing process and its three key phases of planning, implementation, and control - How does the marketing mix help businesses create market segments?
The topic is heart & neck vessels : The topic is heart & neck vessels (cardiovascular) 1. What effect does respiration have on the heart and why? 2. How does venous blood return to the heart?
Comparison of the traditional business type : We will focus on a comparison of the traditional business type (brick-and-mortar stores) versus the internet business type (e-commerce). Discuss the pros and cons of these two business types
Define and describe bell-lapadula and clark-wilson : Provide a description of the selected organization and touch points where data and databases exist to secure and guarantee integrity. Define and describe Bell-LaPadula and Clark-Wilson, and choose at least 1 other security model of your choice to de..
Which vulnerability should be evaluated : If an organization has three information assets to evaluate for risk management purposes as shown in the accompanying data, which vulnerability should be evaluated for additional controls first
Development of an individual during adolescence : What developmental milestones and behaviors signify an adolescent's attempt to transition from parental dependence to independence?
What is the osi model and why is it important : What is the OSI model and why is it important in understanding networking and What are the advantages of using a theoretical model to describe networking
What makes soil rich in north china and why is it important : What makes the soil rich in Northern China and why is it important?
Definition of the main objectives of the business process : A Comprehensive description of the business process including: definition of the main objectives of the business process

Reviews

Write a Review

Management Information Sys Questions & Answers

  Information technology and the changing fabric

Illustrations of concepts from organizational structure, organizational power and politics and organizational culture.

  Case study: software-as-a-service goes mainstream

Explain the questions based on case study. case study - salesforce.com: software-as-a-service goes mainstream

  Research proposal on cloud computing

The usage and influence of outsourcing and cloud computing on Management Information Systems is the proposed topic of the research project.

  Host an e-commerce site for a small start-up company

This paper will help develop internet skills in commercial services for hosting an e-commerce site for a small start-up company.

  How are internet technologies affecting the structure

How are Internet technologies affecting the structure and work roles of modern organizations?

  Segregation of duties in the personal computing environment

Why is inadequate segregation of duties a problem in the personal computing environment?

  Social media strategy implementation and evaluation

Social media strategy implementation and evaluation

  Problems in the personal computing environment

What is the basic purpose behind segregation of duties a problem in the personal computing environment?

  Role of it/is in an organisation

Prepare a presentation on Information Systems and Organizational changes

  Perky pies

Information systems to adequately manage supply both up and down stream.

  Mark the equilibrium price and quantity

The demand schedule for computer chips.

  Visit and analyze the company-specific web-site

Visit and analyze the Company-specific web-site with respect to E-Commerce issues

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd