Risk Classification
Throughout the document, vulnerabilities or risks are labeled and
categorized as:
- Extreme
Extreme risk of security controls being compromised with the possibility
of catastrophic financial/reputational losses occurring as a result.
- High
High risk of security controls being compromised with the potential for
significant financial/reputational losses occurring as a result.
- Elevated
Elevated risk of security controls being compromised with the potential
for material financial/reputational losses occurring as a result.
- Moderate
Moderate risk of security controls being compromised with the potential
for limited financial/reputational losses occurring as a result.
- Low
Low risk of security controls being compromised with measurable negative
impacts as a result.
Please note that this risk rating system was taken from the Penetration Testing Execution
Standard (PTES). For more information, see:
http://www.pentest-standard.org/index.php/Reporting.