...

Vulnerability

Threat-source

Threat Action

Category of Harm

Likelihood

Impact

Impersonation

Common Criminal, Identity Thief

Impersonation with intent to defraud

Inconvenience, distress or damage to standing or reputation

 

 

 

 

Financial loss or agency liability

 

  Low: general criminals won't have subject area expertise to discover a fraud opportunity and there are probably much more attractive targets

Low: impersonated parties would be likely to notice quickly and impact could be mitigated

Impersonation

Disgruntled industry employee

Impersonation with intent to defraud or defame

Inconvenience, distress or damage to standing or reputation

Moderate: industry employee would have the means, but risk exposure is not significantly different in electronic transactions than it is in paper transactions

Low: impersonated parties would be likely to notice and impact could be mitigated

 

 

 

Harm to agency programs or public interest

 

 

 

 

 

Unauthorized release of sensitive information

 

 

 

 

 

Civil or criminal violations

 

 

Repudiation to escape accountability

Customer (fisher or processor)

Signer claims "I didn't sign that"

Inconvenience, distress or damage to standing or reputation

 

 

 

 

 

Financial loss or agency liability

 

 

 

 

 

Harm to agency programs or public interest

 

 

 

 

 

Unauthorized release of sensitive information

 

 

 

 

 

Civil or criminal violations

 

 

 

 

 

Inconvenience, distress or damage to standing or reputation

 

 

 

 

 

Financial loss or agency liability

 

 

 

 

 

Harm to agency programs or public interest

 

 

 

 

 

Unauthorized release of sensitive information

 

 

 

 

 

Civil or criminal violations

 

 

 

 

 

Inconvenience, distress or damage to standing or reputation

 

 

 

 

 

Financial loss or agency liability

 

 

 

 

 

Harm to agency programs or public interest

 

 

 

 

 

Unauthorized release of sensitive information

 

 

 

 

 

Civil or criminal violations

 

 

 

 

 

Inconvenience, distress or damage to standing or reputation

 

 

 

 

 

Financial loss or agency liability

 

 

 

 

 

Harm to agency programs or public interest

 

 

 

 

 

Unauthorized release of sensitive information

 

 

 

 

 

Civil or criminal violations