December 2007
68 posts
The Visibility of Information Risk Management →
I picked up today’s WSJ and got a cold, hard dose of reality.  In it, is an article called “Data Security Breaches Reach a Record in 2007″.  It’s a fairly retrospective article that discusses the four to eight-fold increase in compromised records for EOY 2007 vs. EOY 2006 (the discrepancy in increase estimates is due to Attrition.org using deposition information from Visa & Mastercard in the...
Dec 31st
test →
Dec 29th
Considerations on risk modeling →
As Alex discussed a couple of weeks ago, Mike Rothman posted an article discussing concerns he has with risk management models. In his article, Mike reminds us that risk management is not a silver bullet, that we should only do as much risk modeling as is necessary in order to achieve our goals (I assume he means the organization’s goals), and that calculating risk to the Nth degree doesn’t keep...
Dec 29th
@rmogull: Raving Rabbids 2 for wii is what the boys have been playing all day
Dec 25th
Dec 24th
My Brazilian Football name? "Huttisco" →
Dec 22nd
Developing a timeline. Tried using Numbers.app, now just winging it in OmniGraffle. Gotta love OmniGraffle. Oh, and Cut Copy is teh r0x3rZ
Dec 21st
Staufs is now playing Get The Balance Right: http://tinyurl.com/yntsdv [http://tinyurl.com/yntsdv]
Dec 21st
@soldierant: you’re on. Somebody needs to bring a powerchord though!
Dec 21st
Ah, Staufs dark roast
Dec 21st
When Security Gets Cute →
From Engadget: LG’s USB Vaccine.  It’s a little usb stick with anti-malware!  Isn’t that cute?  It’s like a hypodermic for your PC!
Dec 21st
@sharplefthander how long will you be @staffs? I’ll be there around 1pm
Dec 21st
@soldierant you still@staffs?
Dec 20th
HOLY CRAP: http://scalzi.com/whatever/?p=216 [http://scalzi.com/whatever/?p=216]
Dec 19th
Risk, Art, & Science →
Recently the “Is Risk Management(sic) an art or science” meme has reappeared.  Our response should be: “Bzzt.  Sorry, wrong question.” Not only are they confusing two different disciplines (the study of risk to the study of the management of risk), but they are usually completely off base in their approach to the problem.  whenever I hear this question, three things come to mind: 1.  SCIENCE...
Dec 19th
@mcwresearch: “I don’t care how excrementally runny it is. Fetch hither the frommage de la belle France my good man!”
Dec 18th
Buying bread from a man in Brussels - he was, 6’4” and full of muscles.
Dec 18th
Despite “The Wedding Singer” Billy Idol should be taken out back and put out of his misery for his remake of “LA Woman”
Dec 18th
@Beaker: I can’t stop you, I can only hope to contain you.
Dec 18th
Data Centrism, De-Perimeterization, and Fanaticism →
First, - yes, yes we know.  Rothman went and dissed risk analysis.  At least Mike was kind enough to mention FAIR.  There may be a more reasoned response to that article may be coming in the next few days, but Mike does say one thing I’d like to address right now: The reality is that nearly all risk-modeling approaches force you to make estimates based on assumptions that are in turn based on...
Dec 18th
@bokardo: why is he dangerous? Got a blog post on it?
Dec 18th
I admit it. I like Enterprise.
Dec 18th
@bokardo: dang! Safari 3 just needs session saving for me to use it instead of Camino - still need Firefox for the web dev extension.
Dec 18th
@bokardo: I promise I never had those issues with Bon Echo. Are you on 10.5?
Dec 17th
@mcwresearch: It’s a low frequency risk, you’ll be fine ;)
Dec 15th
@mcwresearch: So are the thieves at the TSA who inspect your baggage :)
Dec 15th
@beaker: You’re just not right.
Dec 14th
@Beaker: “Ouch, quit it.”
Dec 14th
@soldierant: Japanese Spiderman is better (or at least authentic) http://tinyurl.com/2b5cvg [http://tinyurl.com/2b5cvg]
Dec 14th
@bokardo: It’s built for intel (or g5) so it’s natively faster. You can also have aqua widgets :)
Dec 14th
@bokardo: http://tinyurl.com/26rxzs [http://tinyurl.com/26rxzs]
Dec 14th
@mcwresearch: JK
Dec 13th
@mcwresearch: No way, I’m 59.32.232.161 and I’m going to keep trying until my fingers bleed!!!
Dec 13th
@mcwreseearch: No way, I’m 59.32.232.161 and I’m going to keep trying until my fingers bleed!!!
Dec 13th
Great-er Depression coming: Yes or no?
Dec 13th
@bokardo: Let me know if you need help. I do have a few great security contacts
Dec 13th
Randomizing? →
I’m giving a FAIR training class until Friday, so some light link blogging for now: Post by Yale economist Ian Ayres on the Freakanomics blog:  “Why Don’t Sports Teams Use Randomization?” Which begs the question, “Is randomization a tool we can use in our efforts to prevent/detect/respond?”
Dec 12th
And of course, the bachelor Xmas Tree: http://tinyurl.com/3xphez [http://tinyurl.com/3xphez]
Dec 12th
Funny Craigslist post: http://www.craigslist.org/about/best/phi/471580402.html [http://www.craigslist.org/about/best/phi/471580402.html]
Dec 12th
Some Serious Data Security Efforts →
If you haven’t seen Wired’s article on Pixar’s data security efforts, you should check it out.  Apparently they can do their job under what most would consider draconian security policies.  Pretty cool.  Two things I would like to point out: First, many of these efforts would be considered to be “risk management” by many (see this weekends blog post), myself included.   But I think they would be...
Dec 10th
quartz backgrounds on presentation crashes leopard. nice.
Dec 8th
Security Management vs. Risk Management →
Security (Management) Focuses on protection (prevention, detection, response) Risk (Management) is influencing the risk condition of an organization in a desired manner (by making well-informed decisions) I really like that second bit. Influencing the risk condition of an organization. What do you think?
Dec 8th
The world will soon have 7 more new FAIR certified risk analysts. I’m stoked
Dec 8th
Insomnia kind of sucks. But then again, I can get some work done
Dec 7th
@soldierant you really should. Watch out for vultures though.
Dec 6th
@bokardo that’s about my schedule. Tough at first, but worth it in the long run.
Dec 6th
Finally set up Gmail IMAP and Mail.App to work together properly….
Dec 6th
@wii Thanks for the Holiday Wii Giveaway! Wii Transfer looks cool: http://wiitransfer.com/ [http://wiitransfer.com/]
Dec 6th
I’m here, at Stuafs, waiting for my 8am to show. It’s, like, 12 degrees outside
Dec 6th
@wii: I’d like to win a Wii, please!
Dec 6th