Activity-in-Diagram: Perform or Update MBCRA

CreatorTim Ramey

Description

The CyWG selects an MBCRA methodology to evaluatethe mission risk and inform a prioritized risk-based tasting approach for Phases 3 and 4. The assessment also includes determining the likelihood of every identified exploitation technique, which comprises the threat capability and required level of effort as well as many attributes of the attack surface and path vulnerabilities. Evaluate the impact of the exploitation on the mission to include the perspective of system operators and defenders. The likelihood and impact assessments will result in a prioritized risk assessment.

Owning Diagram A22: Analyze the Attack Surface

Input

cyber threat scenario

anticipated cyber effects

Mission-Based Cyber Risk Assessment (MBCRA)

Output

cyber-attack vectors

cyber-attack targets

Control

Cheif Developmental Tester

plan for MBCRA

Mechanism

Cybersecurity DT&E Technical Experts