[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fd3PvHy6BqrmrGx1CuFv84y-tGoYhxCAKdS6ar5BtqPs":3,"faq-section-":53},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":7,"wordCount":8,"readTime":9,"title":10,"nbDownloads":11,"excerpt":7,"lang":12,"url":13,"intro":14,"featured":4,"state":15,"author":16,"authorId":17,"datePublication":21,"dateCreation":22,"dateUpdate":23,"mainCategory":24,"categories":44,"metaDatas":50,"imageUrl":7,"imageThumbUrls":51,"id":52},false,"ISO 27005 defines risk as \"potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm to the organization.\" ISO 31000 states that risk is the \"effect of uncertainty on objectives.\" \r\n\r\nA source of risk can be a person, internal or external to the organisation, acting accidentally or deliberately (e.g. IT administrator, user, external attacker, competitor), or a non-human source (e.g. water, dangerous materials, non-targeted computer virus) who may be the source of a risk.\r\n \r\nRisk sources can be of different kinds:\r\n \r\n**Internal human source**\r\n \r\nThis could be :\r\n \r\n- a malicious employee, using his or her proximity to the system, skills, privileges and potentially high time availability, or committing negligence due to a possible lack of training and awareness.\r\n- a careless or ill-intentioned user or those around them who have access to the service.  \r\n\r\nThere may be many reasons for this: clumsiness, error, negligence, revenge, a desire to alert, malice, greed, espionage, etc.\r\n\r\n**External human source**\r\n \r\nThis may be :\r\n\r\n- a malicious or ignorant third party using their physical proximity to fraudulently access the service\r\n- an attacker targeting a user by using his knowledge of the user and some of the information concerning him\r\n- an attacker targeting one of the companies in charge of data processing, using their knowledge of the companies to damage their image\r\n- an authorised third party using its privileged access to illegitimately access information. The motives can be multiple: gambling, nuisance, malice, revenge, espionage, greed, acquisition of data with a view to exploiting it, etc.\r\n\r\n**Non-human source**\r\n \r\nThis could be an incident or disaster at one of the organisations in charge of processing (power cut, fire, flood, etc.).","\u003Cp>ISO 27005 defines risk as \"potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm to the organization.\" ISO 31000 states that risk is the \"effect of uncertainty on objectives.\"\u003C/p>\r\n\u003Cp>A source of risk can be a person, internal or external to the organisation, acting accidentally or deliberately (e.g. IT administrator, user, external attacker, competitor), or a non-human source (e.g. water, dangerous materials, non-targeted computer virus) who may be the source of a risk.\u003C/p>\r\n\u003Cp>Risk sources can be of different kinds:\u003C/p>\r\n\u003Cp>\u003Cstrong>Internal human source\u003C/strong>\u003C/p>\r\n\u003Cp>This could be :\u003C/p>\r\n\u003Cul>\r\n\u003Cli>a malicious employee, using his or her proximity to the system, skills, privileges and potentially high time availability, or committing negligence due to a possible lack of training and awareness.\u003C/li>\r\n\u003Cli>a careless or ill-intentioned user or those around them who have access to the service.\u003C/li>\r\n\u003C/ul>\r\n\u003Cp>There may be many reasons for this: clumsiness, error, negligence, revenge, a desire to alert, malice, greed, espionage, etc.\u003C/p>\r\n\u003Cp>\u003Cstrong>External human source\u003C/strong>\u003C/p>\r\n\u003Cp>This may be :\u003C/p>\r\n\u003Cul>\r\n\u003Cli>a malicious or ignorant third party using their physical proximity to fraudulently access the service\u003C/li>\r\n\u003Cli>an attacker targeting a user by using his knowledge of the user and some of the information concerning him\u003C/li>\r\n\u003Cli>an attacker targeting one of the companies in charge of data processing, using their knowledge of the companies to damage their image\u003C/li>\r\n\u003Cli>an authorised third party using its privileged access to illegitimately access information. The motives can be multiple: gambling, nuisance, malice, revenge, espionage, greed, acquisition of data with a view to exploiting it, etc.\u003C/li>\r\n\u003C/ul>\r\n\u003Cp>\u003Cstrong>Non-human source\u003C/strong>\u003C/p>\r\n\u003Cp>This could be an incident or disaster at one of the organisations in charge of processing (power cut, fire, flood, etc.).\u003C/p>\r\n",null,286,2,"Sources of risk",0,"en","sources-of-risk","What do the sources of risk mean?","Published",{"id":17,"displayName":18,"avatarUrl":19,"bio":7,"blogUrl":7,"color":7,"userId":17,"creationDate":20},38,"Paul-Emmanuel Bidault","https://static.dastra.eu/tenant-27/avatar/38/paul-emmanuel-bidault-150.jpg","2019-12-03T19:09:28","2023-12-27T14:19:49.549","2023-12-27T15:19:48.1868394","2023-12-28T13:50:34.7918708",{"id":25,"name":26,"description":27,"url":28,"color":29,"parentId":7,"count":7,"imageUrl":30,"parent":7,"order":11,"translations":31},21,"Glossary","Definition of every word used by Dastra","glossary","#643bb0","https://static.dastra.eu/tag/b308b9d3-37af-4e92-8354-ab8adec1740a/documentation-1000.png",[32,36,40],{"lang":33,"name":34,"description":35},"fr","Glossaire","La définition de tous les termes utilisés dans Dastra",{"lang":37,"name":38,"description":39},"es","Glosario","La definición de todos los términos utilizados en Dastra",{"lang":41,"name":42,"description":43},"de","Glossar","Die Definition aller in Dastra verwendeten Begriffe",[45],{"id":25,"name":26,"description":27,"url":28,"color":29,"parentId":7,"count":7,"imageUrl":30,"parent":7,"order":11,"translations":46},[47,48,49],{"lang":33,"name":34,"description":35},{"lang":37,"name":38,"description":39},{"lang":41,"name":42,"description":43},[],[],56350,[]]