Network Vulnerability Assessment Methodology 63
Determining the actual risk in terms of real potential loss to a particular
asset requires a clear understanding of what is sensitive and critical to the
enterprise. This is why careful interviewing of staff in Phase II and close
collaboration with top management and network administrators throughout
the NVA process are so important.
Bear in mind that the analysis needs to meet the business objectives or
mission of the enterprise. The more you communicate with the business units
and users during the NVA process, the more they will understand the context
in which the final recommendations are communicated. In the end, what the
sponsor wants to know is how to protect the business and what needs to be
done ...