Practical Threat Analysis Reports
The following is a list of
the reports that are part of the PTA Professional Edition tool. You are
invited to download and install the tool at the
Free Practical Threat
Analysis Download page - the PTA Help file that comes with the
software provides detailed and updated description of the tool's
features and reports. Visit the
PTA Professional
Edition Latest Updates page for more information on latest changes
and product versions history.
Analysis Reports
Read More:
http://www.ptatechnologies.com/PTAReports.htm
System’s Status
Provides a “bottom
lines monitor” of the threat analysis project with an updated view of the Risk
Status of the system, as well as indications regarding the progress
of the threat analysis process.
The Total Value of Assets, Total Cost of Countermeasures
and the amount of money that is Already Invested in Mitigation
provides bottom line important financial figures.
Top Current Risk Threats is a bar chart presentation of the
current top 5 risky threats. The risk values are displayed in $. The
names of the threats are displayed in the details table below the bar
chart.
Risk History is a graph which displays the levels of risk in the
system along the time axis of the threat analysis process. The levels of
various risks are presented in percentage of the total value of system
assets.
Analysis History is a graph that displays the numbers of
threat model entities e.g. vulnerabilities, threats and countermeasures defined in the model along
the time axis of the threat analysis process.
Read More:
http://www.ptatechnologies.com/PTAReports.htm
Countermeasures Cost-Effectiveness
Shows a list of
countermeasures sorted according to their Theoretical Cost-Effectiveness
that is based on the assumption that all countermeasures will be
implemented. Since this assumption is, in most cases, not practical, it
is recommended to complement the results of this report with the results
of Optimized Risk Reduction Plan analysis report.
For each countermeasure, the report displays calculative parameters such
as cost-effectiveness, implementation cost and overall mitigation. In
addition, each countermeasure is accompanied by a list of the
vulnerabilities it mitigates.
Mitigation Plans by ROSI
This report produces a
list of mitigation plans for threats sorted in a descending order by
their ROSI value. ROSI - Return On Security Investment -
is a very common quantitative criterion for comparing security
solutions.
Read More:
http://www.ptatechnologies.com/PTAReports.htm
Optimized Risk Reduction Plan
This analysis report produces a
recommended sequence of mitigation steps that will reduce the system’s
risk to a given target level in the most cost-effective way. Each step
in the plan is comprised of countermeasures that should be implemented
in order to achieve the step’s contribution to risk reduction.
Read More:
http://www.ptatechnologies.com/PTAReports.htm
Customized Reports
Detailed Threats
This report produces a
list of all the system’s threats, ordered by their Current Risk Level.
It shows all assets, vulnerabilities, countermeasures, entry points,
attacker types and tags associated with each threat.
In addition, it displays the relevant calculative parameters such as
maximal, minimal and current risk levels, threat’s probability, level of
damage, and the maximal mitigation level available for the threat.
Detailed Assets
Shows a detailed list of
all assets ordered by their Maximal Risk Level. For each asset
the report displays its Weighted Value and its Maximal, Minimal
and Current Risk values. In addition, the report
displays the threats that threaten each of the assets and their relevant
calculative parameters such as Level of Damage and Threat’s
Probability.
Detailed Vulnerabilities
Shows a detailed list of
all vulnerabilities ordered by their IDs and the threats associated with
each of the vulnerabilities.
Detailed Countermeasures
Shows a detailed list of
all countermeasures ordered by their IDs and the vulnerabilities and threats associated with
each of the vulnerabilities.
Top Threats by Current Risk
This report produces a
chart of top risky threats, ordered by their Current Risk Level.
The threats’ names and their risk values in $ are displayed above the
chart.
Read More:
http://www.ptatechnologies.com/PTAReports.htm
Customized Reports
If you wish to provide
threat analysis reports tailored to your clients’ needs, we offer
personalized, private professional development programs. For more
information please contact
Zeev Solomonik
or have a look at our Solutions for Security Consultants and Service Providers.
***
PTA Software Tools
for Practical Threat Analysis
Home Page