tailieunhanh - security assessment case studies for implementing the nsa iam phần 10
Ví dụ, nếu một lỗ hổng tồn tại nhưng không có mối đe dọa khai thác của lỗ hổng đó, nguy cơ tổng thể là thấp. Nếu một lỗ hổng tồn tại, một mối đe dọa tồn tại để khai thác lỗ hổng, và nếu nó là một hệ thống quan trọng, một đánh giá mức độ cao nên được xem xét để phát hiện. | Tying Up Loose Ends Chapter 11 389 What Was Good Positive results should be put on your Good are processes that you might never have tried before during an assessment but that worked out well. These include such things as the change in interview style we mentioned earlier. Another example might be a new interviewer on the team who performed well and can added to the list of team leaders for your company. Our goal is to identify the good attributes of our assessment process. Note Good lessons are just as important to understand as the negatives lessons. I ve seen many organizations that approach the analysis of lessons learned as a pessimistic activity that generally only points out negative activities. This couldn t be further from a healthy approach. The truth of the matter is that the process needs at least as much positive reinforcement as negative. Consider some of the activities that might have seemed spur of the moment when they were performed but eventually added value to the assessment process. This is important because it reassures team members that individual thought about the way our process assessment unfolds is a good attribute. Team members with positive attitudes will do much more to improve the process than those with negative attitudes. What Requires Improvement Negative results should be put on your Poor list. Negative items might include processes that perform poorly in certain situations or the lack of a needed process aren t necessarily things you ve known about for months which is why we call them lessons team will pick up these tidbits of information through experience and from assessing a variety of customers and industries. In actuality you should view these lessons as positive since they give the team an opportunity to improve immature processes. 390 Chapter 11 Tying Up Loose Ends Utilizing Lessons Learned Now you ve created these lists of the lessons you ve learned during the .
đang nạp các trang xem trước