Bypassing Security Control for VIPs !

Risk Vs Threat Vs Vulnerability 

Its connected to previous posts and thoughts...
On many Organizations to satisfy the personalities seems bypassing Security controls for VIPs where i refer those VIP are high value assets and crown jewel of organizations. 
Controls we are deploying should be process oriented not personal oriented. Agree IT is to support Business, Of-course. But in this new era many business undoubtedly connected to NET and its should protected. 
Referring to RISK equation as below;
 Risk = Threat * Vulnerability * Asset Value 
In Simple language : forgot the Car key in side the Car is an Vulnerability, threat here is where we put the car & key, in City or Village, ie how potential on vulnerability. Asset value is what kind car we using Maruti or Ferrari :) .
The term “vulnerability” refers to the security flaws (Weakness ) in a system that allow an attack to be successful. Threat is the frequency of potentially adverse events.
High value asset need more protection. 
And Servers are not only high value assets ! 
Come to Tech Scenario we may protecting all by great walls and finally giving the great hole ! on the great walls by "Dispensations"
** Above all are my personal viewpoints and Views.
Ecosystem activist as printing it on flex and papers!!!

Comments

Popular posts from this blog

‘Lazy’ in pet name called comfort!!

Slideshare link for my public presentations

Security Incident Hand-off