Best practices in assessing and mitigating vulnerabilities
For some of the vulnerability concepts we've gone through earlier in this chapter, I've included ways to mitigate against those vulnerabilities. None of those mitigations takes into consideration your own organization, its threats, the value of the assets, or the likelihood of exploitation. I've just essentially listed off ways you might have seen other organizations mitigate against those risks, and potentially a few good ideas came to you that way.
In this section, I would like to continue in that fashion, but I first want to stress how important it is to apply the necessary amount of mitigations in order to reduce down to an acceptable level. That's the name of the game here! Save yourself the money and headaches involved with making a system completely risk-proof when it doesn't face any threats or isn't valuable to you or a threat actor.
With that said, I can get back into how we can...