>Question: Should I be concerned about a finding that has a low severity
>rating but the risk factor is high?  Why isn't a finding that has a high
>risk factor rated with a high severity rating?  I have seen lots of findings
>like this that have a low severity rating but a high risk factor.  Just does
>not make sense to me.  What is the logic behind Nessus doing this?

Your CIO has the right idea - you can't fix 10,000 problems in a week, but you 
might be able to handle the top 10. Anyway, it's up to *you* to decide what 
your top 10 are. Things like SNMP don't bug me as much, because my domain is 
internal security. I'd much rather spend time fixing the problems on our few 
externally available servers with a "low" severity than most of the "high" 
severity problems on the internal machines, simply because of exposure. Just 
look at where the risks come from - if it takes a highly sophisticated attack 
from the inside, it's probably more worth your time to secure access from the 
outside to machines on the inside, as most users wouldn't be able to do it 
themselves.


Reply via email to