Vulnerability Analysis - Business Case
摘要
Vulnerability analysis of an organization’s assets is one of the basic tools for security risk management. In particular, the Microsoft Center Configuration Manager tool was used for vulnerability analysis, which was based on the concept of ISO/IEC 27007, in two rounds of measurements - the time interval of both measurements was about eight months – 07/22 the 1st round, 03/23 the second round. The organization’s vulnerability rating was done on a scale from 1 to 10, where values from 8 to10 represented critical vulnerabilities. The statistical functions of Microsoft Excel and the R programming language were mainly used for the analysis. The results of the analysis showed in the first round the use of unauthorized software, a large number of vulnerabilities immediately after the installation of the software and therefore a poor use of the additional installation of security patches. Only 22% of secure computers in the organisation were identified. The subsequent second round showed a very substantial improvement in the protection of the organisation’s assets –85% of secure computers. Our research demonstrably confirmed that it is necessary to perform risk analysis periodically, especially due to changes in vulnerabilities in time. This could be due to software updates or new threats emerging in cyberspace.