| |
|
Exposure definition
An exposure is a state in a computing system (or set of systems) which is not a universal vulnerability, but either:
Allows an attacker to conduct information gathering activities or to hide activities
Allows an attacker to hide activities
Includes a capability that behaves as expected, but can be easily compromised
Is a primary point of entry that an attacker may attempt to use to gain access to the system or data
Is considered a problem according to some reasonable security policy .
|
|
|