Question

In: Computer Science

Risk analysis is one way to monitor security in an organization. Risk analysis can be a...

Risk analysis is one way to monitor security in an organization. Risk analysis can be a time- consuming process; it involves a number
of steps, some of which require “educated guessing.” Nevertheless, the process alone raises awareness of security issues even if no immediate actions are taken as a result. The steps are:

i. Identify assets (infrastructure, people, hardware, software, reputation, etc.).

For the rest of this list, we’ll concentrate on a single asset.

ii. Determine vulnerability (what event or events might happen to the asset. For example, the building could catch fire, the website could be hacked, etc.).

For the rest of this list, we’ll concentrate on a single asset vulnerable to a single event.

ii. Estimate the probability per year of this event (based on past data, expert estimates, etc.). Take current security measures into account.

iv. Estimate the expected cost if this event occurs (cost to repair or replace, cost of lost business, etc.).

v. Compute risk exposure 5 cost estimate 3 probability estimate.

vi. Identify any additional security measure X that would help protect against this event, determine what it would cost, and do a calculation of the risk exposure with the additional security measure X in place.

vii. Do a cost-benefit analysis:
(Risk exposure without X – Risk exposure with X) − Cost of X

You have a small web-based business that uses a single server to manage your webpage and your customer information. Over the past four years, your website has been hacked and taken down twice. You estimate that the cost of this event is $600 to clean the server and reload the webpage and $12,000 in lost business while the server is down.

  1. You could purchase a backup server for a cost of $3,000, which you estimate would reduce the probability per year of losing your website to 0.2. Would this be a cost- effective security measure?

  2. What if you reevaluate the probability per year with the backup server to be 0.3. Does this change your answer?

Solutions

Expert Solution

Solution:-


Related Solutions

One way a creditor can perfect a security interest is _____________ . a. by filing a...
One way a creditor can perfect a security interest is _____________ . a. by filing a UCC-1 with the correct government office (in Texas, the Secretary of State). b. by creating a Purchase Money Security Interest which perfects automatically. c. all of the answers are ways a creditor can perfect a security interest. d. by the secured party taking possession of the debtor’s collateral.
One way to identify use of methamphetamine in a population is to monitor the waste water....
One way to identify use of methamphetamine in a population is to monitor the waste water. Methamphetamine is excreted from the body up to 23% unchanged and can cause unintended environmental exposures. It has been detected in the sewage of all major cities, even after sewage treatment. Methamphetamine is organic base with a pKaof 10.0 [12]. a. Many sewage treatment facilities induce pH ranges from pH 5 to pH 10 to encourage degradation. Is methamphetamine charged at these extremes? Also,...
One-Way ANOVA and Multiple Comparisons The purpose of one-way analysis of variance is to determine if...
One-Way ANOVA and Multiple Comparisons The purpose of one-way analysis of variance is to determine if any experimental treatment, or population, means, are significantly different. Multiple comparisons are used to determine which of the treatment, or population, means are significantly different. We will study a statistical method for comparing more than two treatment, or population, means and investigate several multiple comparison methods to identify treatment differences. -Search for a video, news item, or article (include the link in your discussion...
How can an organization determine a risk score?
How can an organization determine a risk score?
What are ways to monitor risk management?
What are ways to monitor risk management?
In what ways can the Earned Value Analysis method be used to monitor the project in...
In what ways can the Earned Value Analysis method be used to monitor the project in an integrated way without affecting the overall schedule and budget of a project?
what is one way of measuring risk in the stock market?
what is one way of measuring risk in the stock market?
Details on how you can test for risk and conduct a security assessment using CCTV security...
Details on how you can test for risk and conduct a security assessment using CCTV security camera? Also, explain the risk mitigation?
Practice Exercise 14: One -way Analysis of Variance (ANOVA) Use the One-way ANOVA function in SPSS...
Practice Exercise 14: One -way Analysis of Variance (ANOVA) Use the One-way ANOVA function in SPSS to answer the questions based on the following scenario. Select Descriptives from the Options menu to obtain the means and standard deviations. (Assume a critical level of significance of .05). Researchers are interested in determining if the type of medication influences the number of days it takes for symptoms to cease. Thirty-six patients are randomly assigned to receive Brand X, Brand Y, or Brand...
Discuss different security websites or network and security informational sites that you may already monitor and...
Discuss different security websites or network and security informational sites that you may already monitor and why. Limit the discussion to no more than three sites.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT