Andy Jaquith’s new excellent book, Security Metrics is a must-read for any anyone even slightly interested in getting more scientific about the Art of Security or perhaps even looking to rise up in unison against subjective, biased, sometimes excellent, oft-times not, auditors and other security reviewers that second guess everything you do. Your risk management decisions are always associated with the question “is it worth it?” and therefore must at least implicitly include a judgement call about value for every decision you make. So if your decision process includes “winging it” then you can pretend to ignore value and loss, but you really haven’t - you’ve just made it so personal and malleable as to create ambiguity everywhere and justify anyone’s position.
Posted on Thursday, April 19th, 2007 at 7:19 pm and under category News.
You can read any responses through the RSS 2.0 feed.
You can give a response, or trackback from your site.
Leave a Reply
You must be logged in to post a comment.
Search
Recent Posts
- Peculiar Patch Pits iPhone Security vs. Safari
- Web Fraud 2.0: Faking Your Internet Address
- US Army bans USB devices to contain worm
- Computer virus quarantines London Hospital for second day
- Lame Mac Trojan limps into view
- ‘Network Identity Theft’ Politely Avenged
- PC virus forces three London hospitals into computer shutdown
Categories
Monthly Archives
- November 2008 (44)
- October 2008 (54)
- September 2008 (40)
- August 2008 (66)
- July 2008 (60)
- June 2008 (51)
- May 2008 (57)
- April 2008 (82)
- March 2008 (60)
- February 2008 (46)
- January 2008 (41)
- December 2007 (20)
- November 2007 (37)
- October 2007 (36)
- September 2007 (27)
- August 2007 (39)
- July 2007 (34)
- June 2007 (77)
- May 2007 (142)
- April 2007 (722)
- March 2007 (2124)
- February 2007 (612)