The InfoSec Blog
System Integrity: Context Is Everything
Navigation
  • About The Author
  • Presentations
  • System Integrity
You are here: Home › Archive for May 2010
Currently browsing

May 2010

“Impact” is not a Metric

28 May, 2010 | Filed under: Failures, Human Factors, Politics & Economics, Risk, Security, Social

I never like to see the term ‘impact’. Its not a metric. I discuss how length, temperature, weight, are metrics whereas speed, acceleration, entropy are derived values. In the same sense, ‘impact’ is a derived value – “the cost of the harm to an asset”. The value of an asset …

Risk Analysis Makes No Sense … does it?

22 May, 2010 | Filed under: Failures, Rants and Raves, Risk, Security

Image via Wikipedia Take a look at this article. http://www.zdnet.com/blog/security/security-engineering-broken-promises/6503 You’re back?  What did you think of it? OK, now look again, scroll down the section titled “Risk Management“.  It picks up on a number of themes I’ve discussed and has this interesting observation: Prioritization of security efforts is a …

Risk is Not a Primary Metric

19 May, 2010 | Filed under: Failures, Human Factors, Rants and Raves, Risk, Security

“Risk” is not a primary metric. What do I mean by that? Primary metrics you can measure easily. In physics they are things like length, weight, temperature, time-duration. Secondary metrics most people can understand: rate of change that we call speed (length as distance and elapsed time). Some secondary and …

The Classical Risk Equation

19 May, 2010 | Filed under: Failures, How-to, Rants and Raves, Risk, Security, Standards

What we had drilled into us when I worked in Internal Audit and when I was preparing for the CISA exam was the following RISK is the PROBABILITY that a THREAT will exploit a VULNERABILITY to cause harm to an ASSET R = f(T, V, A) Why do you think …

Calendar

May 2010
M T W T F S S
« Mar   Jun »
 12
3456789
10111213141516
17181920212223
24252627282930
31  

Search

Archives

Tag Cloud

Access control Apple Botnet Business Business Continuity Planning Certified Information Systems Security Professional CISSP Computer security Confidence trick Consultants controls Donn Parker Editing English language FMEA fraud HP Individual Standards Information security infosec International Organization for Standardization IPad IPhone ISO/IEC 27001 Laptop laptops Law Linux Malware Management Microsoft Open source owasp Policy Risk Risk analysis Risk assessment Risk Management Security Site Management Standards statistics Technology United States Vulnerability

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

Popular Pages

  • The Classical Risk Equation
  • Separation of Duties: Infosec, IT and Audit
  • “Cybercrime” is still Crime and “Cyberfraud” is still Fraud
  • Risk Analysis makes no sense … Does it?
  • Are *you* ready to give up yet?
  • Why InfoSec Positions go unfilled
  • Security
  • Risk

Categories

Advisories & Vulnerbilities

  • bugtraq @ insecure.org
  • SANS Security Alerts
  • SANS Storm Center
  • Secunia Advisories
  • Symantec Security Response – Advisories
  • Symantec Security Response – Resent Viruses

Blogroll

  • Augusto Paes de Barros
  • Bob Johnston
  • Daniel Accioly Rosa
  • Deep Litter
  • DHS Daily Report
  • Eduardo Neves
  • Emergent Properties
  • Gary Hinson
  • Hayden’s Harangues
  • Martin McKeay
  • Schneier on Security
  • The Quiet Earth
  • The Security Team
  • Watchguard Wire

Security Links

  • CERT-CC
  • E2K Security
  • focus-ids @ insecure.org
  • fulldisclosure @ insecure.org
  • Identity mangement news
  • Incidents
  • InfoWorld- Security
  • isn @ insecure.org
  • joatBlog
  • Kill-HUP.com
  • Mark O’Neill’s Radio Weblog
  • microsoft @ insecure.org
  • Microsoft TechNet – Security
  • MSDN- Security
  • Network World Fusion NetFlash
  • Network World on Privacy
  • Network World on Security
  • Network World on Wireless Security
  • nmap-hackers @ insecure.org
  • Scott Granneman- Intellectual Property
  • Scott Granneman- Privacy
  • Scott Granneman- Security
  • Scott Loftesness- Digital Identity
  • Security Blog
  • Stupid Security
  • THE Network Security Blog – Geek Troy Jessup
  • Wi-Fi Networking News
  • Wifi Security Project

© 2013 The InfoSec Blog

Powered by Esplanade Theme by One Designs and WordPress