~/ learn/ comp-400/ cards/ Building a risk register for a home network
1 of 4

In a home-network register entry for malware corrupting data files, which existing control is the one that changes the CONSEQUENCE rating rather than the likelihood?

In a home-network register entry for malware corrupting data files, which existing control is the one that changes the CONSEQUENCE rating rather than the likelihood?

Answer

an offline, versioned backup with a tested restore

Options - A. an offline, versioned backup with a tested restore - B. a current anti-malware engine on every general-purpose device - C. operating-system and application auto-update - D. NAT with default-deny inbound on the household router Why - A. Correct — it does nothing to stop the worm arriving or executing, but it decides how much harm follows when one does. - B. Anti-malware stops the sample executing, so it reduces likelihood. The files are just as important if it fails. - C. Auto-update closes the vulnerability the worm would exploit — a likelihood control. - D. Default-deny inbound removes an arrival vector, so again likelihood. Every control pulls one of three levers: reduce the vulnerability, reduce the threat source’s capability or motivation (both lower likelihood), or reduce the magnitude of the impact (lowers consequence). Naming the lever for each control is what makes a register defensible.

Stallings & Brown 5e ch14 §14.4–14.5; ISO/IEC 27005

space flip · ← → navigate · esc to exit
NORMAL ~/memra/library/7321e22f-9a05-4b24-806d-9786469ef828/flashcard utf-8 LF