Project Definition ◾ 59
© 2011 by Taylor & Francis Group, LLC
are some possible reasons why a system function might be excluded from a security
risk assessment:
◾ Function Is Not Security-Relevant—Some system functions (or applications)
are not relevant to a specically targeted security risk assessment. Such non-
relevance should not be confused with nonimportance. For example, a word-
processing application or a custom application for creating and submitting
timecards may not be security-relevant and can be safely ignored in a security
risk assessment. Most word processors operate on behalf of the user who called
the program and do not operate in a privileged state. In this case, the worst
the word processor can do is mangle your document, ...