From the course: CSSLP Cert Prep: 4 Secure Software Implementation

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Addressing risks

Addressing risks

From the course: CSSLP Cert Prep: 4 Secure Software Implementation

Start my 1-month free trial

Addressing risks

- Finding risks is important, but not nearly as important as actually addressing those risks. Fortunately, risk management doesn't require an all or nothing approach. You have multiple options for how you can address those risks. Before we dive into risk management techniques, though, I want to spend a moment on the concepts of vulnerability and risk. These two terms are sometimes used interchangeably, but I strongly encourage you to avoid that trap. A vulnerability is a weakness that if exploited could enable an attacker to do harm. When we use the term risk, though, it goes deeper than that. Risks take vulnerabilities into account and then add context to them. A risk includes a measurement of how likely an attack is to succeed, as well as the measurement of the potential damage that might result. Those measurements are crucial when it comes to prioritizing your actions and determining which risk management technique…

Contents