tag:blogger.com,1999:blog-4088979.post704495722923552905..comments2023-10-16T06:06:25.012-04:00Comments on TaoSecurity Blog: Brothers in RiskRichard Bejtlichhttp://www.blogger.com/profile/13512184196416665417noreply@blogger.comBlogger4125tag:blogger.com,1999:blog-4088979.post-80642448587084795422007-09-15T17:23:00.000-04:002007-09-15T17:23:00.000-04:00Thanks for the nice post!Thanks for the nice post!Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-53705704744785574902007-01-09T12:34:00.000-05:002007-01-09T12:34:00.000-05:00Thanks Richard, for more concrete info for those o...Thanks Richard, for more concrete info for those of us "in the trenches". It's so hard to find USEFUL info sometimes that it almost makes me want to find another career path. I totally agree that it's vital that we as security professionals use a common taxonomy to avoid confusion and loss of credibility. Your blog is the first thing I check in the morning-I hope to take one of classes someday, but since I'm way out here in Hawaii, I might have to settle for your books...Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-17697744164845013272007-01-08T20:00:00.000-05:002007-01-08T20:00:00.000-05:00That was a nice little vignette. I especially like...That was a nice little vignette. I especially liked the paragraph on value, which in my opinion is the most ignored portion of the risk equation. Unfortunately once you get away from some of the core or highly used infrastructure extracting the actual value of an asset can be difficult. Especially when you have implicit dependencies e.g. an alerting system which relies on it's own mail server that is rarely used. <br /><br />A good way to gauge value is to theoretically remove the asset from the network and try to determine what fails or to actually do that if you can "risk" it. Please excuse the pun.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-49792104008378927562007-01-08T19:56:00.000-05:002007-01-08T19:56:00.000-05:00Thanks Richard!
I've been enjoying the metrics th...Thanks Richard!<br /><br />I've been enjoying the metrics thread, btw...Anonymousnoreply@blogger.com