Methodology for Defining Security
Strategies
The following section discusses a
methodology for defining a computer security strategy that can be
used to implement security policies and controls to minimize
possible attacks and threats. The methods can be used for all types
of attacks on computer systems, whether they are malicious,
non-malicious or natural disasters, and can thus be re-used
repeatedly for different attack scenarios. The methodology is based
on the various types of threats, methods of attack, and
vulnerabilities. The following flow chart outlines the
methodology.

|