Exploring a Controls-Based Assessment of Infrastructure Vulnerability

نویسندگان

  • Oliver J. Farnan
  • Jason R. C. Nurse
چکیده

Assessing the vulnerability of an enterprise’s infrastructure is an important step in judging the security of its network and the trustworthiness and quality of the information that flows through it. Currently, low-level infrastructure vulnerability is often judged in an ad hoc manner, based on the criteria and experience of the assessors. While methodological approaches to assessing an organisation’s vulnerability exist, they are often targeted at higher-level threats, and can fail to accurately represent risk. Our aim in this paper therefore, is to explore a novel, structured approach to assessing low-level infrastructure vulnerability. We do this by placing the emphasis on a controls-based evaluation over a vulnerability-based evaluation. This work aims to investigate a framework for the pragmatic approach that organisations currently use for assessing low-level vulnerability. Instead of attempting to find vulnerabilities in infrastructure, we instead assume the network is insecure, and measure its vulnerability based on the controls that have (and have not) been put in place. We consider different control schemes for addressing vulnerability, and show how one of them, namely the Council on Cyber Security’s Top 20 Critical Security Controls, can be applied.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

CDT Technical Paper 02/14 Controls-Based Assessment of Infrastructure Vulnerability

Assessing the vulnerability of an enterprise’s infrastructure is an important step in judging the security of a network and the trustworthiness and quality of the information that flows through it. Currently real-world infrastructure vulnerability is often judged in an ad hoc manner, based on the criteria and experience of the assessors. While methodological approaches to assessing infrastructu...

متن کامل

Introducing the Flood Vulnerability Index (FVI) as a flood crisis management tool

Background and objective: Floods are among the most dangerous natural disasters that causes loss of life and property every year. The destructive effects of floods are more documentedو due to climate change and increasing economic and social development. Social and infrastructural vulnerabilities have also increased due to human settlement adjacent to river floodplains. Therefore, to prevent mo...

متن کامل

Desertification risk assessment and management program

Risk assessment provides the possibility of planning and management to prevent and reduce the risk of desertification. The present study is aimed to assess the hazard and risk of desertification and to develop management programs in the semi-arid western regions of Golestan Province in Iran. Desertification rate was obtained using the Iranian model of desertification potential assessment. Since...

متن کامل

Evaluation of Ecological Vulnerability in Chelgard Mountainous Landscape

Although complexity and vulnerability assessment of mountain landscapes is increasingly taken into consideration, less attention is paid to ecophronesis-based solutions so as to reduce the fragile ecosystem vulnerability. The main propose of this study is to provide an insight of mountain complex landscape vulnerability and propose ecophronesis-based solutions in strategic planning framework fo...

متن کامل

Rapid Vulnerability Assessment of Lavizan Urban Forest Park

Although the vulnerability assessment of forest parks is used to determine the threats they face, a rapid and holistic framework has not been established well. The primary objective of this study is to adopt a framework for rapid assessment of forest parks vulnerability, examined in Lavizan forest park in Tehran (Iran) as the case study. The vulnerability assessment has been conducted, using th...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015