– The difficulty in managing security threats and vulnerabilities for small and medium-sized enterprises (SME) is investigated. A detailed conceptual framework for asset and threat classifications is proposed. This framework aims to assist SMEs to prevent and effectively mitigate threats and vulnerabilities in assets. The framework models security issues in terms of owner, vulnerabilities, threat agents, threats, countermeasures, risks and assets, and their relationship; while the asset classification is a value-based approach, and threat classification is based on attack timeline. Keywords— security threats, computer networks, vulnerabilities, asset classification
Cyril Onwubiko, Andrew P. Lenaghan