Presentation is loading. Please wait.

Presentation is loading. Please wait.

Understanding the Security Vulnerability Assessment Copyright Jean Perois, CPP, PSP, FSyI.

Similar presentations


Presentation on theme: "Understanding the Security Vulnerability Assessment Copyright Jean Perois, CPP, PSP, FSyI."— Presentation transcript:

1 Understanding the Security Vulnerability Assessment Copyright Jean Perois, CPP, PSP, FSyI

2 ‘ Have a clearer picture of what the SVA (API Methodology) is about, understand what it can do for you, but also evaluates both its strengths and limits.’ Copyright Jean Perois, CPP, PSP, FSyI Today’s objectives:

3 Security Audit Risk Assessment Security Survey Copyright Jean Perois, CPP, PSP, FSyI

4 What is an SVA? The SVA is a systematic process that evaluates the likelihood that a threat against a facility will be successful. Copyright Jean Perois, CPP, PSP, FSyI

5 What can the SVA do for you? 1. Full assessment of the security posture of your company 2. It measures vulnerabilities against threats 3. It identifies security gaps 4. Recommendations are commensurate to security risk Copyright Jean Perois, CPP, PSP, FSyI

6

7

8

9

10 * Based on Vulnerability, Threat & Attractiveness variables

11 Copyright Jean Perois, CPP, PSP, FSyI

12 Vague, unscientific and outdated Vague, unscientific and outdated R = P x C versus R = P A * (1 - P E ) * C R = P x C versus R = P A * (1 - P E ) * C where P A is the likelihood of adversary attack,, P E is security system effectiveness,1 - P E is adversary success, and C is consequence of loss of the asset.But The SVA addresses the full spectrum of mitigation measures The SVA addresses the full spectrum of mitigation measures Security remains a conceptual exercise and about educated guesses and probabilities Security remains a conceptual exercise and about educated guesses and probabilities Using equations will not change the reality of Risk Using equations will not change the reality of Risk

13 Copyright Jean Perois, CPP, PSP, FSyI


Download ppt "Understanding the Security Vulnerability Assessment Copyright Jean Perois, CPP, PSP, FSyI."

Similar presentations


Ads by Google