My article, “Maddening Methods: Fundamentals of Risk Assessment and Analysis,” was published in the July 2010 edition of The ISSA Journal. It covers some of the key concerns around risk assessment today, including addressing common arguments posited against risk assessments and risk management. From the abstract: Considerable confusion exists in the security industry around the effectiveness of risk assessment and analysis methodologies. Points of contention often focus on specific attributes of a given method, such as data quality, statistical analysis, or a qualitative versus quantitative approach. There are reasonable, viable answers to these points of contention that resolve most of these concerns. I hope that you’ll find this piece informative and enjoyable.
Author: Ben Tomhave
I recently had a project to help spec out a DLP project for a customer from a high-level perspective. Having never done anything with DLP previously I embarked on a research mission. What I found was interesting. There’s not much out there on the intarwebs. As such, I thought I’d offer a few quick suggestions, just in case you want to go research solutions, too. Start with Securosis! Their reports are freely available, comprehensive, and more informative than anything else I found. Search for Gartner and Forrester reports. While these analyst firms charge for their reports, vendors will often post them for free. Specifically, try these search strings: “forrester wave content security suites” “gartner magic quadrant data loss prevention” Beware[…]
A couple weeks ago, NASA announced it was all but done with certification and accreditation (C&A), calling it “cumbersome and expensive.” Many were intrigued by such a statement – not because it was wrong, but because it represented a potentially interesting shift in the status quo, done in a somewhat rebellious manner. NASA instead favors a “risk-based approach” that relies more heavily on continuous monitoring. NASA also cited significant cost savings from cutting back C&A activities. Seemingly in direct response to this outburst, NIST has now released an update to their continuous monitoring FAQ, specifically pointing out that C&A activities are a necessary component of risk-based management of systems, and highlighting that continuous monitoring alone is insufficient. One of the[…]
The FTC has once again delayed enforcement of the FACTA Red Flag Rules, this time to Dec. 31st, 2010.
I’m greatly amused. In 2008, former Gartner analyst Richard Stiennon said that NAC was worthless (see “Don’t even bother investing in Network Admission Control“). In a face-to-face debate on the topic a couple months later, Joel Snyder allegedly defeated Stiennon on the topic (and quite handily, if you agree with the account by then-NAC-vendor-CTO Alan Shimel). It’s interesting, then, that 2 years later Snyder has come out and basically declared the NAC market a complete mess and not really worth the cost. Said Stiennon in 2008: “Put it this way: Can you secure your network without NAC? Yes. Does NAC in anyway reduce your overall costs? No. Does NAC tie you down to one vendor’s eco-system? Yes, if you go[…]