My name is Constance Lanson. And in these lessons, you will learn threats and vulnerabilities, threat models and threat agents and actions. Let's get started. A company that takes no risk cannot survive or thrive. However, on the other hand, a company that ignores risk will fail with just a single threat is exploited. A threat is any circumstance or event with the probability to cause harm or loss to the organization. A threat can be any act or agent or system that is capable of causing harm. A vulnerability is a weakness in an asset or even an environment. Vulnerabilities are exploitable weaknesses within the organization and within its infrastructure or system. There are innumerable vulnerabilities that exist today, with many being discovered every day. A convenient way to really look at vulnerabilities is to classify them as either hardware, software, or procedural. When you're looking at threats and vulnerability, you are looking at, has that asset been exposed? When you're talking about threats and vulnerabilities, it also is advantageous for an organization to undertake a threat assessment. A vulnerability assessment is great, as it identifies all those threats that may exist. But a threat assessment also is good, because it takes a look at the assets. And by looking at the assets, the company now can make a determination what risk exists toward that asset, and can that threat be exposed to a possible vulnerability? There are different types of threats. There are intentional threats and unintentional threats. Those intentional threats are often performed by perpetrators who are intending to cause harm to the organization. There also are unintentional types of threats. One unintentional type of threat can be a human threat. Maybe that data entry clerk simply made a sleight of the hand keystroke mistake. Although that data entry was a mistake, that mistake could lead to some type of vulnerability within the system. Another unintentional threat could be just a simple minor mishap. Maybe that particular technician forgot to lock the server room door when they left out of the server room. Leaving that door unlocked is a threat that can lead to a potential vulnerability. Also, you have simple failures. When you're talking about failures, you're looking at equipment failures. Maybe the air conditioning broke, maybe the server broke. Any of those failure in equipment will result in a loss of availability, and result in downtime. And loss of availability not only to the system, to the network, but also to data. And another category of an unintentional threat is environmental. Those are non-man threats, such as weather. Floods, volcanoes, and those type of natural disasters are what we consider as an unintentional environmental threat that can lead to a vulnerability. There are two primary vulnerabilities within an organization that they should mitigate, and one of those are what we call password cracking attacks. These are attacks that are against unsecured passwords, unsecured storages. Many times, end users use passwords that are easy to type and easy to remember. These make a perfect threat that leads to a vulnerability because of password cracking attacks. Also, end users are the biggest vulnerability within a organization. These end users, along with poor use of passwords, also provide threats and vulnerabilities that may be unintentional. Three primary threats that exist against an organization also are password cracking attacks, and this includes the guessing and deciphering of a user's passwords, because those users also create passwords that are easy to remember and easy to write. Another threat that should be also addressed and mitigated is heightened access, which means the user or the attacker will log into one system on the one level of access, but attempt to log into another system using a higher level of access. And a third threat that should be mitigated within an organization is social engineering. And social engineering involves the use of manipulation or even trickery to convince the end user to perform some action or even to divulge sensitive information to the attacker, itself. These threats often lead to vulnerabilities that have been exposed toward the asset that always lead to some level of risk within the organization. The threats to confidentiality, integrity, and availability of information has evolved to a vast collection of events that include both intentional and unintentional threats. Confidentiality, the availability, or basically, for the organization to provide information, information that has been protected from disclosure or even exposure to unauthorized individuals or systems. When looking at integrity, the integrity of information that is threatened when that data or information has became corrupted or exposed. In corruption, also, for data can occur while it's being transmitted or even stored. Availability. Availability, having people to have access to those systems, to that data without interference or obstruction. So when you're looking at the security triad, CIA, unlike any other organization, this particular triad helps organizations in identifying threats that could lead to vulnerabilities and expose risk to the organization. Organizations expend a lot of manpower, money, and thousands of hours to maintain their information, assets, against threats and vulnerabilities. If threats did not exist, these resources really could not be used exclusively to improve the systems. So however we look at threats and vulnerabilities, we always must understand these will be a constant concern, and the need for every organization in their security will continue to grow, along with the sophistication of the attacks on the assets in the form of threats and vulnerabilities. Thanks for watching the lesson on threats and vulnerabilities.