Brothers in Risk
I write about risk, threat, and other security definitions fairly regularly. Lo and behold I just read a post by someone else who shares my approach. This is a must read. How did you react to the story?
A second brother in risk is Gunnar Peterson, who writes in part:
When security teams conflate threats and vulnerabilities, the result is confusion. Instead efforts dealing with threats... and vulnerabilities... should be separately optimized, besides both being part of "security"; they don't have that much in common.
Oh bravo, especially the old school link to Dan Geer which I should read again.
A second brother in risk is Gunnar Peterson, who writes in part:
When security teams conflate threats and vulnerabilities, the result is confusion. Instead efforts dealing with threats... and vulnerabilities... should be separately optimized, besides both being part of "security"; they don't have that much in common.
Oh bravo, especially the old school link to Dan Geer which I should read again.
Comments
I've been enjoying the metrics thread, btw...
A good way to gauge value is to theoretically remove the asset from the network and try to determine what fails or to actually do that if you can "risk" it. Please excuse the pun.