错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Identification of Cyber Threats

  • Alexander Olsen

摘要

When identifying threats, companies should consider any specific aspects of potential threat actors’ capability, opportunity, and intent to attack. This can include using, for example, an external person or an insider as an unintentional middleman unknowingly carrying the threat, e.g., on an infected USB stick. Once identified, threats should be considered alongside identified vulnerabilities to evaluate the likelihood of an attack or incident taking place. Together with the impact of a given incident, the likelihood of the incident occurring produces the risk factor. Organisations and individuals can constitute an intentional or even unintentional threat to the safety and security of a crew, the environment, and the ship. The following figure lists examples of threat actors and their possible motivations and objectives. The list is non-exhaustive. Such threat actors will have varying degrees of skills and resources to potentially threaten the safety and security of ships and a company’s ability to conduct its business.