Information Technology Reference
In-Depth Information
table 4.2 tpA rating Guide
TPA 
Parameter
0
1
2
3
4
Means
No means, no budget, no
knowledge, no
equipment
Known to have a low
degree of funding,
knowledge, and access
to equipment; may have
a little of each of these,
but not enough to be a
serious threat
Known to have some
degree of funding,
knowledge, and access
to equipment; may have
one of two
Known to have a high
degree of funding,
knowledge, and access
to equipment; may have
two of three
Fully funded, full
knowledge, possession,
or easy access to
equipment
Method
No methods, no prior
activity
Known for some probing;
use of some scripts; no
sophistication
Known for some attack
sophistication; some
manual, mostly canned
scripts
Known for high attack
sophistication
Fully capable of
performing attack; there
are known methods and
history of performance
Motivation
No known reasons to
attack
Attacker motivation is
more one of casual
opportunity
Attacker is somewhat
motivated to attack your
country and entities like
yours; not speciically
motivated to launch an
attack now or in the
near future
Attacker is highly
motivated to attack your
type of organization and
has been known to do
so; no speciic
knowledge of your
organization as a
speciic target
Fully motivated to carry
out an attack; attacker is
known to hate or
otherwise desire to
attack your organization;
history of prior attacks
Mission
No known targets
General knowledge of
adversary interest in
your organization; no
speciic knowledge of
adversary desires and
no rational guesses
Adversary objectives are
not easily guessed and
may include Web site,
R&D, inancial
information, strategic
planning, databases,
etc.; mission may be
denial of service,
stealing information, or
violating any of the IA
core principles
Adversary objectives
toward your
organization may be
guessed with a high
level of conidence, e.g.,
you are a bank, they
want the money
Full knowledge of
adversary desired
targets and desired
effect on those targets;
this requires speciic
knowledge of adversary
intent
 
Search WWH ::




Custom Search