Vulnerability assessments aim to identify security flaws and likely attack scenarios in order to improve security, but they can be challenging for security managers due to fears about vulnerabilities being uncovered. Design reviews provide a less frightening alternative that still allows for security improvements. A design review briefly reviews design issues and offers recommendations, while identifying fewer vulnerabilities than a full assessment. However, about half of organizations that do a design review later pursue a more comprehensive vulnerability assessment once they see the initial results. The author suggests design reviews or market analyses as ways to introduce vulnerability issues in a palatable manner for hesitant organizations.
Related topics: