Estimated time for attacker to successfully penetrate system = 25 minutes
Estimated time to detect an attack in progress and notify appropriate information security staff = 5 minutes (best case) to 10 minutes (worst case)
Estimated time to implement corrective actions = 6 minutes (best case) to 20 minutes (worst case)
Solution: XYZ Company is secure under their best case scenario but they do not meet security requirements under their worst case scenario.
P = 25 Minutes
D = 5 Minutes (Best Case) 10 Minutes (Worst Case)
C = 6 Minutes (Best Case), 20 minutes (Worst Case)
Time-base model: P > D + C
Best Case Scenario P is greater than D + C (25 > 5 + 6)
Worst Case Scenario P is less than D + C (25 < 10 + 20)
Share with your friends: |