AND QUESTIONS
Threat Sources - Adversarial - malicious
Accidental - errors by users
Structural - failures of hardware, software, or other equipment
Environment - Natural disasters or structural failures
Unauthorized aka Black Hat - Criminal hackers who break computer security for personal gain or
other malicious purposes
Authorized aka White Hat - Security experts who study and practice hacking for legal purposes such
as finding countermeasures against other hackers (ethical hacking)
Semi-authorized aka gray hat - hackers who are neither authorized or malicious don't do harm
believe they improve computer security
Attacker qualities - Intent/Motivation
Sophistication/Capability level
Resources/funding
Location - outside attackers/ inside attackers
Target information - open
source intelligence
Script kiddies - unskilled hackers who rely on commonly available attack tools including mailicious
scripts
Hacktivists - attack organizations to further political or ideological messages; some are considered
cyberterrorists
criminal syndicates - seek financial gain and work as part of a larger organization
, competitiors - unethical businesses attack competitors commit industrial espionage or sabotage
valuable resources
Insiders - Many attacks are caused by employees or former employees who have retained network
access
Nation-states - cyber warfare organizations dedicated to rivals
Advanced Persistent Threats (APT) - an attack type against a particular organization with high value
data change threat vector over time mostly used by nation states and most sophisticated criminal
organizations
Attack Vectors - how a threat might contact your organization
DIrect Access - can directly contact your resources (easiest if it is an insider)
Wired/wireless networks - includes remote access, data breaches, and network service outages
Attack vector - Email/Personal Communications - communication tool can be used to attack the
organization (email most common)
AV - social media - scan for personal information and spread disinformation
AV -supply chains - organizations's vendors can be used to attack you; share data/access network
AV -removable media and mobile devices - anything that can be inserted into network can be used to
attack you
AV - cloud services - just a service on someone else's computer
Artificial intelligence risks - machine learning uses algorithems to analyze large data sets to recognize
patterns and relationships can be manipulated and predictions used against it
Third party risks - There are many ways a relationship with a third party presents risks - supply chain
interruptions, connections to your network can create vulnerabilities, if you store your data with
them that poses risks