Finding and fixing vulnerabilities in information systems : the vulnerability assessment & mitigation methodology /

Corporate Author: United States. Defense Advanced Research Projects Agency.
Other Authors: Antón, Philip S.
Format: Book
Language:English
Published: Vulnerability assessment and mitigation methodology Santa Monica, CA : Rand, 2003.
Series:Rand note ; MR-1601-DARPA
Subjects:
Online Access:http://search.ebscohost.com/login.aspx?direct=true&scope=site&db=nlebk&AN=105337
Table of Contents:
  • Introduction
  • Concepts and Definitions
  • VAM Methodology and Other DoD Practices in Risk Assessment
  • Vulnerability Attributes of System Objects
  • Direct and Indirect Security Techniques
  • Generating Security Options for Vulnerabilities
  • Automating and Executing the Methodology: A Spreadsheet Tool
  • Next Steps and Discussion
  • Summary and Conclusions
  • Appendix: Vulnerability to Mitigation Map Values.