
68 ◾ Information Security Fundamentals
Once the threats have been recorded, the FRAAP documentation will look like
Figure 4.16.
Business
Attribute reat
Integrity Data stream could be intercepted
Integrity Faulty programming could
(inadvertently) modify data
Integrity Copies of reports could be
diverted (written or
electronically) to unauthorized or
unintended persons
Integrity Data could be entered incorrectly
Integrity Intentional incorrect data entry
Confidentiality Insecure e-mail could contain
confidential information
Confidentiality Internal theft of information
Confidentiality Employee is not able to verify the
identity of a client, example:
phone ...