00:01
In this question there are several tasks given for risk identification and we have to answer each of them one by one.
00:08
So for task 1 risk identification for asset 1 online banking system.
00:18
So the threats of asset 1 are unauthorized access to online banking accounts and second one is malicious software targeting online transaction and vulnerabilities is weak password practices and lack of multi -factor or authentifications.
00:44
Now coming to the asset 2.
00:49
So it is automated clearing house ach transfer.
00:54
So in this threats are unauthorized ach transfer and second one is manipulation of ach transaction details.
01:06
Now vulnerabilities is insufficient transaction verification process and second one is lack of transaction validation controls.
01:24
Now after that asset 3 is company user id and password.
01:36
So in this threats are password guessing or brute force attacks and second one is user credentials phishing and vulnerabilities is weak password complexity requirement and lack of employees security training.
01:58
Now coming to the asset 4.
02:04
Employee email accounts.
02:05
So threats are phishing attacks targeting employees and second one is email account takeover.
02:15
Now vulnerabilities is inadequate email filtering for malicious attachment and lack of email authentication mechanism.
02:32
Now coming to the asset 5.
02:35
5 is challenging question system.
02:38
So in this threats are unauthorized access to challenge questions and second one is exploiting weak challenges question and in this vulnerabilities are insufficient variety and complexity of challenge questions and second one is lack of secure challenge question storage.
03:07
Now coming to the task 2.
03:10
Which is risk assessment threats vulnerability assets tva worksheet.
03:18
So in this we have to make our tables and in this table we have to mention asset threat vulnerability and risk rating and in a asset.
03:32
There are some given like online banking system acs transfer user id and password employee email accounts and challenge question system.
03:48
So we see one by one of each of the assets and what is the threat and what is the vulnerability and risk rating of each of them.
04:01
This table is very helpful for reading or analyze the compare between all of them...