Bypassing Security Control for VIPs !
Risk Vs Threat Vs Vulnerability
On many Organizations to satisfy the personalities seems bypassing Security controls for VIPs where i refer those VIP are high value assets and crown jewel of organizations.
Controls we are deploying should be process oriented not personal oriented. Agree IT is to support Business, Of-course. But in this new era many business undoubtedly connected to NET and its should protected.
Referring to RISK equation as below;
Risk = Threat * Vulnerability * Asset Value
In Simple language : forgot the Car key in side the Car is an Vulnerability, threat here is where we put the car & key, in City or Village, ie how potential on vulnerability. Asset value is what kind car we using Maruti or Ferrari :) .
The term “vulnerability” refers to the security flaws (Weakness ) in a system that allow an attack to be successful. Threat is the frequency of potentially adverse events.
High value asset need more protection.
And Servers are not only high value assets !
Come to Tech Scenario we may protecting all by great walls and finally giving the great hole ! on the great walls by "Dispensations"
** Above all are my personal viewpoints and Views.
Ecosystem activist as printing it on flex and papers!!!
Comments
Post a Comment