Network Administrators

You might also like

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 1

.

Network administrators
. Security administrators
. Operations
. Facility records
. Government records and watchdog groups, such as CERT and Bugtraq
A threat is any circumstance or event that has the potential to negatively impact an asset by
means of unauthorized access, destruction, disclosure, or modification. Identifying all potential
threats is a huge responsibility. A somewhat easier approach is to categorize the common
types of threats:
. Physical threat/theft
. Human error
. Application error/buffer overflow
. Equipment malfunction
. Environmental hazards
. Malicious software/covert channels
A threat coupled with a vulnerability can lead to a loss. Vulnerabilities are flaws or weaknesses
in security systems, software, or procedures. An example of a vulnerability is human error. This
vulnerability might lead an improperly trained help-desk employee to unknowingly give a
password to a potential hacker, resulting in a loss. Examples of losses or impacts include the
following:
. Financial loss
. Loss of reputation
. Danger or injury to staff, clients, or customers
. Loss of business opportunity
. Breach of confidence or violation of lawa number of years. During that time the business needs of the final
user will change due to a changing business environment, new
technology requirements, and changes in managerial personnel
and style. Systems must be developed with as much flexibility as
possible both during development and in the final product.
■ Organizational changes during the project. Given the life of many
IT projects, it would be unusual for a project to reach completion
without staff changes. At either the IT or user end, loss of a key
member of the development team can create havoc and seriously
jeopardize the project’s viability.
■ Failure to understand interrelationships between parts of the
organization. In today’s environment, most systems implemented
are designed to be integrated systems treating the business needs
of a disparate group of corporate functions. In many cases management,
even at the director level, are so specialized that they
have no in-depth understanding of how other areas of the business
function. As a result many integrated systems do not adequately
map onto the business functionality required.
■ Over-optimistic file conversions. Acquiring

You might also like