Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Can I adjust the mitigation effectiveness for individual countermeasures instead of having an aggregate value for the whole mitigation plan?

0
Posted

Can I adjust the mitigation effectiveness for individual countermeasures instead of having an aggregate value for the whole mitigation plan?

0

The PTA calculative model treats a threat mitigation set as a holistic solution which provides a given mitigation level only when all the countermeasures in the set are implemented. For example: if you mark countermeasures C1, C3 and C5 as the members of a specific threat mitigation plan (by checking the In Mitigation Plan for the 3 countermeasures in the Threat Details screen) and then set the Maximal Mitigation of the threat to 70%, you will see that the specific threats risk is reduced by 70% only when C1, C3 and C5 are marked as Already Implemented in the appropriate Countermeasure Details screens. You may justifiably argue that in some cases the implementation of C1 solely may provide some substantive mitigation to the threat although less than the maximal mitigation. We support this situation in our Enterprise Edition where the analyst is able to define several mitigation plans for each threat and thus benefit from maximal flexibility in aggregating the countermeasures in a pract

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123