Home > Information Security Magazine > Columns > Researcher Puts Quantitative Measurement on Information Security Threats
EMAIL THIS LICENSING & REPRINTS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Researcher Puts Quantitative Measurement on Information Security Threats
by Michael S. Mimoso
Issue: Mar 2008
printer-friendly
licensing & reprints
< PREV PAGE   |   1  |   2  |   NEXT PAGE  >

A power company's security researchers shed new light on prioritizing threats though quantitative analysis.


Microsoft and Oracle are generous enough to regularly provide severity ratings on vulnerabilities. And automated vulnerability assessment, configuration and patch management tools have made flaw-fixing run of the mill.

That's a good thing.

But we're all resource-strapped, right? And we know those severity ratings aren't universal. My critical flaw is your moderate it-can-wait-until-next-month bug. Can you afford to solely rely on a generic vulnerability scanner to prioritize how your security organization patches systems?

Maybe it makes sense to concentrate more on the threat portion of the risk equation (you know the one: risk = asset value * vulnerability * threat). What if you could put a quantitative score on threats specific to your environment? What if those scores were based on relevant intelligence from law enforcement and some of the best minds in security?

Well, in another testament to the notion that some of the brightest security research is coming out of the nation's critical infrastructure operations, researchers at Pacific Gas and Electric Company in San Francisco have done just that.

Seth Bromberger, manager of information security at PG&E, and his team of security experts have fine-tuned a homegrown methodology for quantitative threat analysis that enables them to prioritize and trend where threats are coming from--something most companies do informally today, mostly on a gut instinct.

Bromberger's motivation at the outset was a better understanding of the threat landscape for critical infrastructures, and a solid score on the NSA's INFOSEC Assurance Capability Maturity Model, or IA-CMM (PG&E earned the second highest rating ever given by NSA). Ultimately, he's developed a threat model that could apply to any organization.

PG&E's methodology begins with a standard definition of a threat agent--which aligns with that used by the DoD--as any person, process or entity that wants to do your organization harm. The secret sauce in this recipe is the proprietary and confidential intelligence from federal and local law enforcement and security experts feeding the methodology.

< PREV PAGE   |   1  |   2  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts