Countermeasures and a closer look at domains

Peter D. Stephenson · Computer Fraud & Security · 2004

As we have noted in previous columns, we are viewing the risk management and assessment process from the perspective of the classic risk model of threats, vulnerabilities, impacts and countermeasures. Last month we addressed impacts and vulnerabilities. This month we will begin to look at the process of applying countermeasures. However, before we can apply countermeasures, we need to take a closer look at the notion of security policy domains as they apply to identifying vulnerabilities. Arguably, this is the most critical step in a FARES analysis: defining the security policy domains. We begin with a review of some basic information security models.

Read the paper · More papers on PaperTik