Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
buherator (buherator@infosec.place)'s status on Thursday, 04-Jan-2024 09:28:55 JSTbuherator @ret2bed @feld @jomo @lorenzofb I'm genuinely curious if there is some standard risk assessment practice to take into account that compromise of n% of users would provide access to data of, say (n^2)% of users (that function obviously doesn't work but you get the idea)?
Same question whether there are best practices for determining a threshold for "enforce MFA" or is it just "if you got breached, you definitely should've enforced it"?