Framing risk
Framing risk for the SSP is also a necessity when identifying cyber risks. Framing risk has much to do with what is, and is not, included in the environment. For example, when we perform an evaluation of a three-tiered application, we include the presentation, logic, and data tiers. These three (or more) systems can be single standalone systems, or they can be clustered together. The application may require a firewall or Web Application Firewall (WAF) to front all incoming connections.
It is important to understand how you frame the environment to ensure that the SSP correctly identifies all of the systems and their components. Figure 9.2 will help clarify this:
Figure 9.2 – Framing risk
Figure 9.2 shows a typical small business environment; we have employees and their desktops on the left and the server environment on the right. It also shows the use of cloud-based services such as SharePoint. The on-premise environment is protected...