Threats, Vulnerabilities, and Mitigations
Across
- 3. An attacker's ability to obtain, maintain, and diversify access to network systems using exploits and malware.
- 6. Configuration that exposes a large attack surface, such as through unnecessary open service ports, weak or no authentication, use of default credentials, or lack of secure communications/encryption.
- 10. Weakness that could be triggered accidentally or exploited intentionally to cause a security breach.
- 12. Product life cycle phase where mainstream vendor support is no longer available.
- 13. A type of attack that falsifies an information resource that is normally trusted by others.
- 15. Demanding payment to prevent the release of information.
- 17. A type of attack that compromises the availability of an asset or business process.
- 22. A hacker operating with malicious intent.
- 23. A type of threat actor that is supported by the resources of its host country's military and security services.
- 25. The ability of threat actors to draw upon funding to acquire personnel, tools, and development of novel attack types.
- 26. The process by which an attacker copies data from a private network to an external network.
Down
- 1. Falsifying records, such as an internal fraud that involves tampering with accounts.
- 2. A type of threat actor who is assigned privileges on the system that cause an intentional or unintentional incident.
- 4. Often used to refer to someone who breaks into computer systems or spreads viruses. Ethical hackers prefer to think of themselves as experts on and explorers of computer security systems.
- 5. An inexperienced attacker that typically uses tools or scripts created by others.
- 7. Computer hardware, software, or services used on a private network without authorization from the system owner.
- 8. A type of threat actor that uses hacking and computer fraud for commercial gain.
- 9. An attack type that will entice a victim into using or opening a removable device, document, image, or program that conceals malware.
- 11. A hacker engaged in authorized penetration testing or other security consultancy.
- 14. A threat actor that is motivated by a social issue or political cause.
- 16. A formal classification of the resources and expertise available to a threat actor.
- 18. The degree of access that a threat actor possesses before initiating an attack. An external threat actor has no standing privileges, while an internal actor has been granted some access permissions.
- 19. Demanding payment to prevent or halt some type of attack.
- 20. A threat actor that causes a vulnerability or exposes an attack vector without malicious intent.
- 21. The end-to-end process of supplying, manufacturing, distributing, and finally releasing goods and services to a customer.
- 24. actor A person or entity responsible for an event that has been identified as a security incident or as a risk.