Skip to main content

Exploring a Controls-Based Assessment of Infrastructure Vulnerability

Farnan, Oliver, Nurse, Jason R. C. (2016) Exploring a Controls-Based Assessment of Infrastructure Vulnerability. In: 10th Risks and Security of Internet and Systems. CRiSIS 2015, July 20-22 2015, Greece. (doi:10.1007/978-3-319-31811-0_9) (KAR id:67498)

PDF Author's Accepted Manuscript
Language: English
Download (205kB) Preview
Official URL


Assessing the vulnerability of an enterprise's infrastructure is an important step in judging the security of its network and the trustworthiness and quality of the information that flows through it. Currently, low-level infrastructure vulnerability is often judged in an ad hoc manner, based on the criteria and experience of the assessors. While methodological approaches to assessing an organisation's vulnerability exist, they are often targeted at higher-level threats, and can fail to accurately represent risk. Our aim in this paper therefore, is to explore a novel, structured approach to assessing low-level infrastructure vulnerability. We do this by placing the emphasis on a controls-based evaluation over a vulnerability-based evaluation. This work aims to investigate a framework for the pragmatic approach that organisations currently use for assessing low-level vulnerability. Instead of attempting to find vulnerabilities in infrastructure, we instead assume the network is insecure, and measure its vulnerability based on the controls that have (and have not) been put in place. We consider different control schemes for addressing vulnerability, and show how one of them, namely the Council on Cyber Security's Top 20 Critical Security Controls, can be applied.

Item Type: Conference or workshop item (Paper)
DOI/Identification number: 10.1007/978-3-319-31811-0_9
Subjects: Q Science
T Technology
Divisions: Faculties > Sciences > School of Computing > Security Group
Depositing User: Jason Nurse
Date Deposited: 03 Jul 2018 13:08 UTC
Last Modified: 01 Aug 2019 10:43 UTC
Resource URI: (The current URI for this page, for reference purposes)
Nurse, Jason R. C.:
  • Depositors only (login required):


Downloads per month over past year