
201risk, vulnerability, and threat ManageMent
FAILURE
POINTS
FAILURE
SCENARIO VULNERABILITY
TYPE OF
ACTION
METHOD OF
EXPLOITATION
TYPE OF
WEAKNESS
User action Pharmacy hub
backup and
archives
generated
sporadically
or not at all;
backups and
archives not
veried and
unreliable
unsecured
backup,
archives
Accidental
Inaction /
Intentional
Indirect Security
Web server Conicts
between COTS
application
and Pharmacy
HUB cause
unpredictable
behavior,
unauthorized
user can
access COTS
applications
COTS
components
installed with
back doors
Accidental
Inaction /
Intentional
Direct Security,
Reliability
VULNERABILITY
SOURCE OF
VULNERABILITY
HAZARD
CONSEQUENCES SEVERITY ...