So it’s early Sunday AM, and I’m getting my RSA Schedule together finally. So here’s what I’m looking forward to this week, leave us stuff in the comments if you’ve identified other cool stuff: =============== Monday: 8 freaking AM – I’m talking with Rich Mogull of @securosis about Risk Management. Fun! Monday is also Metricon, [...]
Filed under: Uncategorized by alex on Sunday, February 26, 2012
2 Comments »
Would be interested in readers thoughts on Ian G’s post here: https://financialcryptography.com/mt/archives/001357.html
Filed under: Uncategorized by alex on Thursday, February 2, 2012 | Social tagging: modeling
7 Comments »
I got an email from my friend John Johnson who is doing a survey about metrics. If you have some time, please respond… ———————————————————————————————————————————————— I am seeking feedback from others who may have experience developing and presenting security metrics to various stakeholders at their organization. I have a number of questions I’ve thought of, and [...]
Filed under: Uncategorized by alex on Monday, January 16, 2012
No Comments »
Via Nathan Yau’s awesome Flowing Data blog.
Filed under: Uncategorized by alex on Tuesday, January 10, 2012
1 Comment »
Norm Marks of the famous Marks On Governance blog has posted his 2012 wishlist. His blog limits the characters you can leave in a reply, so I thought I’d post mine here. 1. Norm Wishes for “A globally-accepted organizational governance code, encompassing both risk management and internal control” Norm, if you mean encompassing both so [...]
Filed under: best practice, Science of Risk Management by alex on Wednesday, December 21, 2011
2 Comments »
From Keith Weinbaum, Director of Information Security of Quicken Loans Inc. https://www.quickenloanscareers.com/web/ApplyNow.aspx?ReqID=53545 From the job posting: WARNING: If you believe in implementing security only for the sake of security or only for the sake of checking a box, then this is not the job for you. ALSO, if your primary method of justifying security solutions [...]
Filed under: Amusements by alex on Thursday, December 8, 2011
1 Comment »
from Biostatistics Ryan Gosling Including my favorite: Thanks to my friend Bob Rudis for the headsup.
Filed under: Amusements by alex on Tuesday, December 6, 2011
No Comments »
In possibly the worst article on risk assessment I’ve seen in a while, David Lacey of Computerworld gives us the “Six Myth’s Of Risk Assessment.” This article is so patently bad, so heinously wrong, that it stuck in my caw enough to write this blog post. So let’s discuss why Mr. Lacey has no clue [...]
Filed under: measurement, Science of Risk Management by alex on Friday, November 25, 2011
5 Comments »
Ben Sapiro showed off his Binary Risk Assessment (BRA) at SecTor recently. While I didn’t see the presentation, I’ve taken some time and reviewed the slides and read through the documentation. I thought I’d quickly give my thoughts on this: It’s awesome and it sucks. IT’S AWESOME That’s not damning with faint praise, rather, it’s [...]
Filed under: Uncategorized by alex on Thursday, October 20, 2011
3 Comments »
I’ve left Verizon. A lot of folks have come up to me and asked, so I thought I’d indulge in a rather self-important blog-post and explain something: It wasn’t about Verizon, but about the opportunity I’ve taken. Wade, Chris, Hylender, Marc, Joe, Dave, Dr. Tippett & all the rest – they were all really, really [...]
Filed under: Uncategorized by alex on Tuesday, August 16, 2011
3 Comments »