A permit-system risk workshop lists 'hackers' as the only entry without linking specific weaknesses in the application or its environment. What is missing for sound risk identification?
Select an answer to reveal the explanation.
Short Explanation
'Hackers' without a vulnerable door is a scary word, not a risk statement. Risk ID needs the who/what that might attack and the crack they could use—old plugins, weak auth, open admin ports. Pair the threat with the weakness or you're just brainstorming villains.
Full Explanation
Risk analysis begins by identifying threats and the vulnerabilities that enable them within a defined asset context. Vague adversary labels without exploitable conditions do not support likelihood, impact, or treatment decisions. Effective workshops map threat sources to concrete weaknesses in people, process, and technology for the permit system.