...
Vulnerability | Threat-source | Threat Action | Category of Harm | Likelihood | Impact | ||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Impersonation | Common Criminal, Identity Thief | Impersonation with intent to defraud | Inconvenience, distress or damage to standing or reputation |
|
|
|
| Financial loss or agency liability |
| Low: general criminals won't have subject area expertise to discover a fraud opportunity and there are probably much more attractive targets | Low: impersonated parties would be likely to notice quickly and impact could be mitigated |
Impersonation | Disgruntled industry employee | Impersonation with intent to defraud or defame | Inconvenience, distress or damage to standing or reputation | Moderate: industry employee would have the means, but risk exposure is not significantly different in electronic transactions than it is in paper transactions | Low: impersonated parties would be likely to notice and impact could be mitigated | ||||||
|
|
| Harm to agency programs or public interest |
|
| ||||||
|
|
| Unauthorized release of sensitive information |
|
| ||||||
|
|
| Civil or criminal violations |
|
| ||||||
Repudiation to escape accountability | Customer (fisher or processor) | Signer claims "I didn't sign that" | Inconvenience, distress or damage to standing or reputation |
|
| ||||||
|
|
| Financial loss or agency liability |
|
| ||||||
|
|
| Harm to agency programs or public interest |
|
| ||||||
|
|
| Unauthorized release of sensitive information |
|
| ||||||
|
|
| Civil or criminal violations |
|
| ||||||
|
|
| Inconvenience, distress or damage to standing or reputation |
|
| ||||||
|
|
| Financial loss or agency liability |
|
| ||||||
|
|
| Harm to agency programs or public interest |
|
| ||||||
|
|
| Unauthorized release of sensitive information |
|
| ||||||
|
|
| Civil or criminal violations |
|
| ||||||
|
|
| Inconvenience, distress or damage to standing or reputation |
|
| ||||||
|
|
| Financial loss or agency liability |
|
| ||||||
|
|
| Harm to agency programs or public interest |
|
| ||||||
|
|
| Unauthorized release of sensitive information |
|
| ||||||
|
|
| Civil or criminal violations |
|
| ||||||
|
|
| Inconvenience, distress or damage to standing or reputation |
|
| ||||||
|
|
| Financial loss or agency liability |
|
| ||||||
|
|
| Harm to agency programs or public interest |
|
| ||||||
|
|
| Unauthorized release of sensitive information |
|
| ||||||
|
|
| Civil or criminal violations |
|
|