
78 ◾ Information Security Fundamentals
Business
Attribute reat Existing Controls
Probability/
Impact
Risk
Level
Acceptable
Level (Yes/No)
Integrity Data stream could be intercepted Vacant ports are disconnected L/M Low Yes
Integrity Faulty programming could
(inadvertently) modify data
Programs are tested before going into production, and
change management procedures are in place. GLBA’s
Information Technology Policies and Procedures Manual
No. 5-11, ISD Documentation; Test Plan and Test Analysis
Report Standard
L/L Low Yes
Integrity Copies of reports could be diverted
(written or electronically) to
unauthorized or unintended persons
M/M Medium No
Integrity ...