Threat List Sample Clauses

Threat List. The used list of potential threats is combined from the European Union Agency for Network and Information Security (ENISA) [1] and from the Austrian Nationally funded project Risk analysis for the information systems of the electric industry with respect to smart meters and privacy [2]. These lists have been joined and consolidated. Table 2 shows the consolidated threat list used for RESOLVD project. PA1 Bomb attack / threat PA2 Fraud PA3 Sabotage PA4 Vandalism PA5 Theft (of devices, storage media and documents) PA6 Information leakage/sharing PA7 Unauthorized physical access / Unauthorized entry to premises PA8 Deliberate detachment of communication lines PA9 Circumvention of case opening sensors PA10 Coercion, extortion or corruption UD1 Lack of Security Awareness by users UD2 Information leakage/sharing due to user error UD3 Erroneous use or administration of devices and systems UD4 Using information from an unreliable source UD5 Unintentional change of data in an information system UD6 Inadequate design and planning or lack of adaptation UD7 Inadequate key management UD8 Vulnerabilities through legacy devices UD9 Accidental detachment of communication lines UD10 Side-Channels in heterogeneous environments UD11 Lack of long-term support for critical devices, maintenance software, operating systems and databases UD12 Cascading effects of subordinate threats UD13 Concept weaknesses in separating office IT and operational (PCS/DCS) networks UD14 Concept weakness in functional component compromises security feature UD15 Flaws in security audits DI1 Disaster (natural earthquakes, floods, landslides, tsunamis) DI2 Disaster (environmental - fire, explosion, dangerous radiation leak) DI3 Fire DI4 Flood DI5 Pollution, dust, corrosion DI6 Thunder stroke DI7 Water DI8 Unfavourable climatic conditions DI9 Major events in the environment DA1 Damage caused by a third party DA2 Damages resulting from penetration testing DA3 Loss of (integrity of) sensitive information DA4 Loss of devices, storage media and documents DA5 Destruction of records, devices or storage media DA6 Information Leakage FA1 Failure of devices or systems FA2 Failure or disruption of communication links (communication networks) FA3 Failure or disruption of main supply FA4 Failure or disruption of service providers (supply chain) FA5 Malfunction of equipment (devices or systems) FA6 Failure of automated control variable setting by smart meters FA7 Insecure Interfaces (APIs) OU1 Lack of resources OU2...