Hone

Lessons · Cybersecurity · severity from impact and scope

Severity: how bad, times how wide

Severity comes from two numbers, how bad the effect is (impact) and how much of the organisation it touches (scope), and multiplying them gives a score everybody rates the same way.

Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.

What it is for

Two analysts called the same incident 'medium' and 'critical' in the same hour, and the manager had to pick. With impact and scope written as numbers with definitions behind them, they would have agreed, and the argument would have been about the facts instead of the feeling.

How to think about it

Rate impact 1 to 5 from a written table (1 nuisance, 5 the business stops or data is exposed). Rate scope 1 to 5 (1 one user, 5 everybody). Multiply. Then read the band off the scale: 1 to 4 low, 5 to 9 medium, 10 to 14 high, 15 to 25 critical.

Worked example

Impact 4: customer data readable by somebody who should not see it
From the table, not from how the morning feels.
Scope 3: one department, about 60 people
How wide, in the same 1 to 5 terms.
4 * 3 = 12, which is high
One number, and a band both analysts read the same way.
Write both numbers on the ticket, not just the band
So the next person can disagree with the rating rather than with you.

Your turn

Impact 5, scope 2. Write the line that gives the severity score.

severity = 5 * 

The trap

Rating severity by how loudly it was reported. The chief executive's laptop and a warehouse laptop have the same impact table; the difference belongs in scope, if it belongs anywhere.

Practise severity from impact and scope on HoneA question on it now, a coding challenge where there is one, and it is remembered for review. Free, no email needed.