Difference between revisions of "Talk:OWASP Risk Rating Methodology"

From OWASP
Jump to: navigation, search
(What about compensating controls?)
Line 1: Line 1:
 
Just editing now... [[User:Vanderaj|Vanderaj]] 12:04, 22 December 2006 (EST)
 
Just editing now... [[User:Vanderaj|Vanderaj]] 12:04, 22 December 2006 (EST)
 +
 +
== What about compensating controls? ==
 +
 +
I think it is worthwhile to factor in compensating controls into likelihood and impact. For example, if the organization implements an XML firewall, it can reduce like likelihood some data-based attacks. Alternatively, if they backup their data every hour, the impact is then reduced.

Revision as of 12:44, 7 February 2007

Just editing now... Vanderaj 12:04, 22 December 2006 (EST)

What about compensating controls?

I think it is worthwhile to factor in compensating controls into likelihood and impact. For example, if the organization implements an XML firewall, it can reduce like likelihood some data-based attacks. Alternatively, if they backup their data every hour, the impact is then reduced.