What's changed: Initial version
4.3Risk management
Covers the difference between a vulnerability (the weakness itself) and risk (measured as likelihood times impact); the idea of ranking risk into low/medium/high/critical; choosing among the four risk responses—accept, reduce, transfer, avoid; and the relationship whereby a higher data classification brings greater risk—learned as the judgment of deciding "what to protect, and how far."
You cannot protect every weakness at once with equal force. Deciding "where" to direct limited budget and time is risk management. Its starting point is properly distinguishing a vulnerability—the weakness itself—from risk, which measures the prospect of that weakness becoming real harm. This section covers the difference between vulnerability and risk, the idea of ranking risk into low/medium/high/critical, choosing among the four risk responses—accept, reduce, transfer, avoid—and the relationship whereby a higher classification of the data handled brings greater risk—learned as the judgment of deciding "what to protect, and how far."
4.3.1Vulnerability and risk are different
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

