<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Carter Codell – CY 5200</title>
    <link>/docs/cy5200/</link>
    <description>Recent content in CY 5200 on Carter Codell</description>
    <generator>Hugo -- gohugo.io</generator>
    <lastBuildDate>Sat, 28 Dec 2019 18:06:54 -0500</lastBuildDate>
    
	  <atom:link href="/docs/cy5200/index.xml" rel="self" type="application/rss+xml" />
    
    
      
        
      
    
    
    <item>
      <title>Docs: Information Security Risk Assessment Basics</title>
      <link>/docs/cy5200module2/lecture2/</link>
      <pubDate>Fri, 17 Jan 2020 09:11:12 -0500</pubDate>
      
      <guid>/docs/cy5200module2/lecture2/</guid>
      <description>
        
        
        &lt;h2 id=&#34;value-of-assets&#34;&gt;Value of Assets&lt;/h2&gt;
&lt;p&gt;The value of assets can be classified as&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;High&lt;/strong&gt; - Extremely grave injury accrues to organization if the information is compromised; could cause loss of life, imprisonment, major financial loss, or require legal action for correction.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Medium&lt;/strong&gt; - Serious injury accrues to organization if the information is compromised; could cause significnt financial loss or require legal action for correction.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Low&lt;/strong&gt; - Injury accrues to organization if the information is compromised; would cause only minor financial loss or require only administrative action for correction.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With this definition of value, Risk is defined as Value times Probability of Failure&lt;/p&gt;
&lt;h2 id=&#34;probability-of-failure&#34;&gt;Probability of Failure&lt;/h2&gt;
&lt;p&gt;There are 5 levels of control effectiveness (inverse of probability failure):&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Control objective documented in a security policy (lowest)&lt;/li&gt;
&lt;li&gt;Security control documented as procedures&lt;/li&gt;
&lt;li&gt;Procedures have been implemented&lt;/li&gt;
&lt;li&gt;Procedures and security controls are tested and reviewed&lt;/li&gt;
&lt;li&gt;Procedures and security controls are fully integrated into a comprehensive program (strongest)&lt;/li&gt;
&lt;/ol&gt;

      </description>
    </item>
    
    <item>
      <title>Docs: Module 2</title>
      <link>/docs/cy5200/module2/</link>
      <pubDate>Mon, 13 Jan 2020 22:47:54 -0500</pubDate>
      
      <guid>/docs/cy5200/module2/</guid>
      <description>
        
        
        
      </description>
    </item>
    
    <item>
      <title>Docs: Module 1</title>
      <link>/docs/cy5200/module1/</link>
      <pubDate>Tue, 07 Jan 2020 09:34:58 -0500</pubDate>
      
      <guid>/docs/cy5200/module1/</guid>
      <description>
        
        
        &lt;ul&gt;
&lt;li&gt;Overview of Cybersecurity and Information Assurance&lt;/li&gt;
&lt;li&gt;Current State of Cybersecurity&lt;/li&gt;
&lt;li&gt;Introduction to Information Security &amp;amp; Risk Management Principles and Practices&lt;/li&gt;
&lt;/ul&gt;

      </description>
    </item>
    
  </channel>
</rss>
