Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sources of service failure #6

Open
rto opened this issue Aug 20, 2020 · 2 comments
Open

Sources of service failure #6

rto opened this issue Aug 20, 2020 · 2 comments

Comments

@rto
Copy link
Contributor

rto commented Aug 20, 2020

I'm looking at some examples to articulate common risk scenarios and uses of OISRU.

One common scenario is around the service unavailability event that can, naturally, have many sources. For example:

  • Criminal or hacktivist are sensible sources for DDoS-type scenarios
  • Compromised supplier is suitable for a supplier outage (e.g. ISP failure)

For a 'wear and tear' or 'component failure' type scenario, my thinking is that the source of this is ineffective internal on the basis that proactive maintenance is required for any machinery/hardware/software/service.

It is, perhaps, a little unfair in the event of a manufacturing defect were failure occurs significantly before the Mean Time Between Failures. Though defects could be considered compromised supplier. (And, hopefully, they may not occur anywhere nearly frequently enough to warrant serious inclusion in the identified risk scenarios.)

Do we consider the current source lists sufficient to cover these type of 'wear and tear' scenarios?

@oracuk
Copy link
Owner

oracuk commented Aug 20, 2020

I am questioning first whether wear and tear of technology components are technology risks rather than information security risks.

I could see a failure of a technology component, especially one supporting a security control, as an event that leads to & contributes to a security risk but I think that is a technology risk.

@oracuk
Copy link
Owner

oracuk commented Aug 20, 2020

I would be pleased to see a technology risk universe (possibly derived from COBIT scenarios) and a privacy risk universe that are compatible with the Information Security risk universe but I think they are separate concerns and I'm not convinced we should extend OISRU. Maybe if we found appropriate privacy and technology experts to contribute we could look at a broader framework.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants