Category: Risk
Everything filed under Risk.
RLRAA - Real Life Risk Assessment Acronyms
All the following newly-minted risk assessment types have been inspired by actual situations. Hopefully you get to stick to just the proper OCTAVE/FAIR/NIST/etc. ones where you…
Crossroad of ERM and the Parallels to IRM
I was reviewing the - er - highlights? - from the ninth ERM Symposium in Chicago over at Riskviews this morning and was intrigued by some of the parallels to the current situation in enterprise security risk management (the ERM symposium…
Behind The Mask : Supporting The New CIO Personas
This morning, @joshcorman linked to an article in the Harvard Business Review " The Conversation " blog that put forth the author's view of The Four Personas of the Next-Genereation CIO . The term persona is very Jungian and literally…
Micropwns :: Risk Microprobabilities for Infosec?
I had not heard the term micromort prior to listening to David Spiegelhalter's Do Lecture and the concept of it really stuck in my (albeit thick) head all…
Post-theft/loss Response & Recovery With Evernote
Last night, the kids left the garage open after sledding all afternoon and I failed to perform my usual rounds due to still being horrendously ill. At some point between 23:00 & 05:30, miscreants did a snatch & grab on some electronics and…
For Everyone Who Thought I Was Just A Zombie
For Everyone Who Thought I Was Just A Zombie — rud.is blog archive
Metricon: Verification versus Validation
Use systemogram to show what systems are supposed to do (very cool visualization for differing views of "security systems…
Metricon: Measuring Metrics Programs (Why Aren't We?)
If metrics are valuable, why aren't we measuring them. Virtually no research on…
Metricon: Software Security's Futures Plural
Metrics are the servants of risk management and RM is about making…
Metricon: Name Server Log Data
"On the use of name server log data as input for security…