3. Risk reduction actions
Once risk analysis methods have highlighted the vulnerabilities of the information system, the next step is to find solutions that will reduce the risk to an acceptable level. This chapter presents some of these solutions.
Depending on the stage at which they intervene in the evolution of the threat, risk reduction actions can be prevention, detection, correction or recovery.
Prevention deals with measures to be taken to avoid a disaster. For example:
raising awareness (among legitimate users) ;
deterrence (e.g. a tattoo covering the body of a message with an indelible electronic watermark);
protection through cryptology (the art of secrecy: hiding the content of a message), steganography...
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
Risk reduction actions