BOOK THIS SPACE FOR AD
ARTICLE AD28. July 2021
This article has been indexed from DZone Security Zone
Identity governance is a fantastic tool to surface and manage risks around authorizations. One of the hardest parts of this is risk scoring. Operational risk is easy to define (likelihood x impact) and we have lots of established practices to help us. Security risk is different as it includes the motivation of the attacker, i.e. security risk = attacker motivation x likelihood x impact.
To compound this further, there is no common way to measure the effectiveness that various security controls (tools) deliver, for instance, how much does a given security investment reduce the likelihood or impact?