08.11.2012 Views

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

UNCLASSIFIED<br />

For the 16 systems tested, the total number <strong>of</strong> patches that were not installed on<br />

the hosts, by system, are shown in Table 2.<br />

(b) (5)<br />

For the 16 systems tested, we performed an analysis <strong>of</strong> the Common Vulnerabilities and<br />

Exposures (CVEs) and risk ratings. CVE is a dictionary <strong>of</strong> publicly known information security<br />

vulnerabilities and exposures. The number <strong>of</strong> weaknesses identified are shown in Table 3, and<br />

the number <strong>of</strong> vulnerabilities are shown in Table 4.<br />

Table 3. Number <strong>of</strong> Vulnerabilities Identified by CVE and Risk Rating<br />

CVE ID No. Risk Rating Number <strong>of</strong><br />

Vulnerabilities<br />

Identified<br />

CVE-2008 High 613<br />

CVE-2008 Medium 1,559<br />

CVE-2009 High 1,109<br />

CVE-2009 Medium 1,466<br />

CVE-2010 High 1,529<br />

CVE-2010 Medium 1,797<br />

CVE-2011 High 3,002<br />

CVE-2011 Medium 1,261<br />

52<br />

UNCLASSIFIED

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!