vulnerability analysis
Home > Midmarket IT Security Definitions - Vulnerability analysis
SearchMidmarketSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

vulnerability analysis



Word of the Day
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


DEFINITION -

Vulnerability analysis, also known as vulnerability assessment, is a process that defines, identifies, and classifies the security holes (vulnerabilities) in a computer, network, or communications infrastructure. In addition, vulnerability analysis can forecast the effectiveness of proposed countermeasures and evaluate their actual effectiveness after they are put into use.

Vulnerability analysis consists of several steps:

  • Defining and classifying network or system resources
  • Assigning relative levels of importance to the resources
  • Identifying potential threats to each resource
  • Developing a strategy to deal with the most serious potential problems first
  • Defining and implementing ways to minimize the consequences if an attack occurs.

If security holes are found as a result of vulnerability analysis, a vulnerability disclosure may be required. The person or organization that discovers the vulnerability, or a responsible industry body such as the Computer Emergency Readiness Team (CERT), may make the disclosure. If the vulnerability is not classified as a high level threat, the vendor may be given a certain amount of time to fix the problem before the vulnerability is disclosed publicly.

The third stage of vulnerability analysis (identifying potential threats) is sometimes performed by a white hat using ethical hacking techniques. Using this method to assess vulnerabilities, security experts deliberately probe a network or system to discover its weaknesses. This process provides guidelines for the development of countermeasures to prevent a genuine attack.

LAST UPDATED: 11 Mar 2009

Read more about vulnerability analysis:
- Primatech, Inc. describes the technical aspects of industrial cyber security vulnerability analysis.
- Diana Kelley explains how to use vulnerability management data effectively.
- Writing.com has published an article entitled 'The Dark Side of White Hat Hacking.'
- This SearchSecurity.com tip looks at vulnerability analysis service providers.
- Mike Chapple explains how to protect your applications from file format vulnerabilities.
- Mike Rothman discusses how to measure security risks, threats and vulnerabilities.


Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
How to make data loss prevention tools affordable and manageable for midmarket
Data loss prevention can work for the midmarket if organizations have streamlined requirements and can easily identify and locate sensitive data.
Examining Conficker: When a worm becomes a botnet
Conficker may be backed by a well funded group or government intending to silently collect information. Though the hype has waned, Conficker could...
Stolen FTP credentials likely in latest website attacks
The latest website attack techniques use stolen user credentials instead of website vulnerabilities to crack websites and spread malware.

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
network scanning  (SearchMidmarketSecurity.com)
port scan  (SearchMidmarketSecurity.com)




About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts