trustedci/OSCRP

Resource/Financial loss

Closed this issue · 5 comments

Where should financial/resource consequences be represented? In the, e.g., hardware asset? As a new link in the data assets?

von commented

E.g. Unauthorized use of commercial web service. Or DDOS of your service.

Consequence is you have fewer resources to do other stuff.

von commented

Ransomware?

Financial loss is easily understood by scientists, perhaps a small paragraph describing consequences that weren't clear from existing incident examples. --Karen

Sounds like we think it should be an asset, and defined in the Asset definition.

von commented

I think specifically in "Intangible and Human Assets"