When opining on security in “the cloud” we, as an industry, speak very much in terms of real and imagined threat actions. And that’s a good thing: trying to anticipate security issues is a natural, prudent task. In Lori McVittie’s blog article, “Risk is not a Synonym for “Lack of Security”, she brings up an [...]
Filed under: Cloud Security by alex on Monday, June 28, 2010 | Social tagging: Cloud > security management
2 Comments »
Longtime readers know that I’m not the biggest fan of GRC as it is “practiced” today. I believe G & C are subservient to risk management. So let me offer you this statement to chew on: “A metric for Governance is only useful inasmuch as it describes an ability to manage risk” True or False, [...]
Filed under: argument, Doing it Differently, Science of Risk Management by alex on Tuesday, December 15, 2009 | Social tagging: GRC > metrics > risk management > risk modeling > risk science > Science of Risk Management > security management > Security Models
15 Comments »
OR TEXAS HB1830S IS SWINEFLU LEGISLATION, IT’S BEEN INFECTED BY PORK! **UPDATE: It looks like the “vendor language” around Section Six has been struck! Given Bejtlich’s recent promises, I thought we’d take a quick but pragmatic look at why risk assessments, even dumb, back-of-the-envelope assessments, might just be a beneficial thing. As you probably know, [...]
Filed under: Legislation, Uncategorized by alex on Thursday, May 7, 2009 | Social tagging: controls > Legislation > risk > security management
7 Comments »