You have the ranked vulnerability risk worksheet for seven assets as shown in the following table, Table 2. 1. a) Compare the risks associated with assets 2 and 5 and comment which one would require greater attention, assuming that uncertainty is 40% and no risk mitigation is applied. [10 Marks] 2. b) Explain how risk is assessed based on the likelihood of adverse events and the effects on information assets when events occur. Table 2 Risk Assessment Loss Asset relative Loss Asset vulnerability magnitude (LM) value (ARV) frequency (LF) 1. Customer service request via e-mail (inbound) E-mail disruption due to hardware failure 55 0.2 11 2. Customer order via Lost orders due to web server 100 0.1 10 SSL (inbound) hardware failure 3. Customer order via Lost orders due to web server or 100 0.1 10 SSL (inbound) ISP service failure 4. Customer service request via e-mail (inbound) E-mail disruption due to SMTP mail relay attack 55 0.1 5.5 5. Customer service request via e-mail (inbound) E-mail disruption due to ISP 55 0.1 5.5 service failure 6. Customer order via Lost orders due to web server 100 0.025 2.5 SSL (inbound) denial-of-service attack 7. Customer order via SSL (inbound) Lost orders due to web server 100 0.01 1 software failure
You have the ranked vulnerability risk worksheet for seven assets as shown in the following table, Table 2. 1. a) Compare the risks associated with assets 2 and 5 and comment which one would require greater attention, assuming that uncertainty is 40% and no risk mitigation is applied. [10 Marks] 2. b) Explain how risk is assessed based on the likelihood of adverse events and the effects on information assets when events occur. Table 2 Risk Assessment Loss Asset relative Loss Asset vulnerability magnitude (LM) value (ARV) frequency (LF) 1. Customer service request via e-mail (inbound) E-mail disruption due to hardware failure 55 0.2 11 2. Customer order via Lost orders due to web server 100 0.1 10 SSL (inbound) hardware failure 3. Customer order via Lost orders due to web server or 100 0.1 10 SSL (inbound) ISP service failure 4. Customer service request via e-mail (inbound) E-mail disruption due to SMTP mail relay attack 55 0.1 5.5 5. Customer service request via e-mail (inbound) E-mail disruption due to ISP 55 0.1 5.5 service failure 6. Customer order via Lost orders due to web server 100 0.025 2.5 SSL (inbound) denial-of-service attack 7. Customer order via SSL (inbound) Lost orders due to web server 100 0.01 1 software failure
Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
Related questions
Question
![You have the ranked vulnerability risk worksheet for seven assets as shown in the following table,
Table 2.
1. a) Compare the risks associated with assets 2 and 5 and comment which one would require
greater attention, assuming that uncertainty is 40% and no risk mitigation is applied. [10
Marks]
2. b) Explain how risk is assessed based on the likelihood of adverse events and the effects on
information assets when events occur.
Table 2 Risk Assessment
Loss
Asset relative
Loss
Asset
vulnerability
magnitude
(LM)
value (ARV)
frequency (LF)
1. Customer service
request via e-mail
(inbound)
E-mail disruption due to hardware
failure
55
0.2
11
2. Customer order via
SSL (inbound)
Lost orders due to web server
hardware failure
100
0.1
10
3. Customer order via
SSL (inbound)
Lost orders due to web server or
100
0.1
10
ISP service failure
4. Customer service
request via e-mail
(inbound)
E-mail disruption due to SMTP
mail relay attack
55
0.1
5.5
5. Customer service
request via e-mail
(inbound)
E-mail disruption due to ISP
service failure
55
0.1
5.5
6. Customer order via
SSL (inbound)
Lost orders due to web server
100
0.025
2.5
denial-of-service attack
7. Customer order via
SSL (inbound)
Lost orders due to web server
100
0.01
1
software failure](/v2/_next/image?url=https%3A%2F%2Fcontent.bartleby.com%2Fqna-images%2Fquestion%2Ffcf6c8ae-e868-4e10-9138-d2b52dfe18c1%2Ff68385c4-d8b7-4410-88b5-54a7e8d89c59%2Fbix2mau_processed.png&w=3840&q=75)
Transcribed Image Text:You have the ranked vulnerability risk worksheet for seven assets as shown in the following table,
Table 2.
1. a) Compare the risks associated with assets 2 and 5 and comment which one would require
greater attention, assuming that uncertainty is 40% and no risk mitigation is applied. [10
Marks]
2. b) Explain how risk is assessed based on the likelihood of adverse events and the effects on
information assets when events occur.
Table 2 Risk Assessment
Loss
Asset relative
Loss
Asset
vulnerability
magnitude
(LM)
value (ARV)
frequency (LF)
1. Customer service
request via e-mail
(inbound)
E-mail disruption due to hardware
failure
55
0.2
11
2. Customer order via
SSL (inbound)
Lost orders due to web server
hardware failure
100
0.1
10
3. Customer order via
SSL (inbound)
Lost orders due to web server or
100
0.1
10
ISP service failure
4. Customer service
request via e-mail
(inbound)
E-mail disruption due to SMTP
mail relay attack
55
0.1
5.5
5. Customer service
request via e-mail
(inbound)
E-mail disruption due to ISP
service failure
55
0.1
5.5
6. Customer order via
SSL (inbound)
Lost orders due to web server
100
0.025
2.5
denial-of-service attack
7. Customer order via
SSL (inbound)
Lost orders due to web server
100
0.01
1
software failure
Expert Solution
![](/static/compass_v2/shared-icons/check-mark.png)
This question has been solved!
Explore an expertly crafted, step-by-step solution for a thorough understanding of key concepts.
This is a popular solution!
Trending now
This is a popular solution!
Step by step
Solved in 2 steps
![Blurred answer](/static/compass_v2/solution-images/blurred-answer.jpg)
Recommended textbooks for you
![Computer Networking: A Top-Down Approach (7th Edi…](https://www.bartleby.com/isbn_cover_images/9780133594140/9780133594140_smallCoverImage.gif)
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
![Computer Organization and Design MIPS Edition, Fi…](https://www.bartleby.com/isbn_cover_images/9780124077263/9780124077263_smallCoverImage.gif)
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
![Network+ Guide to Networks (MindTap Course List)](https://www.bartleby.com/isbn_cover_images/9781337569330/9781337569330_smallCoverImage.gif)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
![Computer Networking: A Top-Down Approach (7th Edi…](https://www.bartleby.com/isbn_cover_images/9780133594140/9780133594140_smallCoverImage.gif)
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
![Computer Organization and Design MIPS Edition, Fi…](https://www.bartleby.com/isbn_cover_images/9780124077263/9780124077263_smallCoverImage.gif)
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
![Network+ Guide to Networks (MindTap Course List)](https://www.bartleby.com/isbn_cover_images/9781337569330/9781337569330_smallCoverImage.gif)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
![Concepts of Database Management](https://www.bartleby.com/isbn_cover_images/9781337093422/9781337093422_smallCoverImage.gif)
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
![Prelude to Programming](https://www.bartleby.com/isbn_cover_images/9780133750423/9780133750423_smallCoverImage.jpg)
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
![Sc Business Data Communications and Networking, T…](https://www.bartleby.com/isbn_cover_images/9781119368830/9781119368830_smallCoverImage.gif)
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY