Estimating likelihood
Now that we have valid threat and vulnerability pairs, we now need to determine the likelihood that a given vulnerability will be acted upon by a threat source.
As you develop your information security program, the estimation of likelihood in this scenario should be a well-established repeatable process. While you can have multiple categories for likelihood, I recommend that you use only three (low, medium, and high). Using three categories keeps things simple and allows you to make a simpler decision, quicker decisions means you can move on to the real task of securing your organization. Ultimately, how many categories you use is dependent on your organizational culture and policies. Be careful when you start moving ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access