Wednesday, February 25, 2009

Appropriate threat-alert form

Contents
In awareness of excerpting when a post is fed to other pages. Common-necessary information would be placed at beginning.
  1. Identification: name, type, risk assessment, (re)solution
  2. Situation/status: impact, preventive/proactive actions, passive action/progress
  3. More details: characteristic, resolution (corrective action)
  4. Other references

Items

Subject: use term "Threat-alert" to be common among virus, security threat, spyware, etc. Then follow by threat's common name.

Labels/tags: attention, computer-security

Identification
  1. Name: threat's full/official name
  2. Type: from which we can determine the threat's major characteristic
  3. Severity: how much disaster the threat can do.
  4. Spreading: how fast/wide can the threat do outbreak.
  5. Difficulty: how long/difficult to remove the threat infection. Note that some case, repairing may not be difficult anymore but still takes long time.
  6. Protection: what are required to protect our systems against the threat.

Situation
  1. Impact: when, where, and how many that infection is found.
  2. Protection deployment status, or any preventive workaround and progress.
  3. Passive action/progress: for ones already got attacked.

More details
  1. Infection, risk condition: what kinds of system, process, characteristic that are risky to be attacked.
  2. Symptom: what can we notice when attacked?
  3. Resolution, correction: how to remove the threat after attack?

Remarks
Comparing risk-assessment attributes with FMEA
  1. Severity: same
  2. Occurrence: not really concerned in operation. We'd rather review current/known impact of each time.
  3. Detect risk: can be determined from "protection": i.e., it is high when protection is not available yet, and it is low when protection is effecient and successfully installed.

NAI/McAfee has a good attribute list -- where?

If quantifiable, risk assessment can be plotted as bubble chart:
  • x = difficulty
  • y = severity
  • z = spreading

No comments:

Post a Comment