February 2008
61 posts
Curphey on BPM | securosis.com →
Feb 29th
Someone to Watch, Over Me…. →
Before we dive back into Deming later this week, I wanted to comment on some discussion we’ve been having over at Chandler Howell’s NBFAC Blog.  Over at Chandler’s podium for all things risky (which, it should be noted, is the original IRM blog) - there’s some discussion about GRC and their meaning and role and purpose.  In my usual manner, I made a hasty, didactic statement to be taken as fact...
Feb 26th
Another View on Deming & Risk Management →
When I had wrote about Deming, I hadn’t realized that Adrian Lane of IPLocks was one step ahead.  He’s written a piece on Deming’s 14 points on the IPLocks.com blog here.
Feb 25th
Clemens Kogler - Le Grand Content →
What an excellent video!
Feb 25th
Barn Door Simple? Not Exactly… →
Scott Wright of Scott Wright’s Security Views Blog wrote recently in his post “A Barn Door Has No ROI”: But how many organizations realize that investing in security safeguards is just like putting a door on a barn. It’s not so much trying to figure out how much money you will save if you put on a door. You know if you don’t put on a door, eventually, you’re going to have to buy a new horse. ...
Feb 21st
Deming and Risk Management →
This morning, Pete Lindstrom sent the following out to the SecurityMetrics.org mailing list:  This book was recommended to me today: How to Measure Anything: Finding the Value of “Intangibles” in Business. It appears to be getting very good reviews (all sockpuppets, I’m sure ;-)). One of the comments says this: Hubbard put forth these four assumptions which I found to be most useful when...
Feb 20th
Discovery Channel Broadcast on Decisions and... →
This link is an .mp3 on the Discovery Channel’s website for a show they did called “Understanding Odds” on decisions and probability.  It’s really good reading, especially their definition of a “good decision” at around minute 23. There’s also an excerpt on YouTube that’s awesome. Great Stuff!
Feb 18th
Data Breach Notification Laws, State By State -... →
Feb 16th
WatchWatch
Video Fantastica! Smoke on the Water
Feb 13th
Feb 12th
Feb 12th
The Effectiveness of the Most Underappreciated... →
Post Summary:  Measuring Control Effectiveness is a tricky thing, as effectiveness is relative to external factors.  Because we don’t have precise measurements for those factors, Control Effectiveness is (you guessed it) a probability issue.  One angle that is usually under-appreciated is the ability of our controls to reduce the probability of action by a threat agent.  More research should be...
Feb 12th
Spire Security Viewpoint: Back of the Envelope... →
Feb 8th
Will ISO 27004 Be Able to Help Us Measure Control... →
A few days ago, when I was much busier being moral support to the Mrs., the Cyberphobia blog wrote an interesting article on ISO 27004.  27004 is all about measuring the effectiveness of our controls. Our anonymous friend at Cyberphobia does a great breakdown “word for word” on the language surrounding 004, I won’t replicate it here but forward you to the site.  Go ahead and click over, I’ll...
Feb 8th
Feb 8th
Ning has no import of RSS or Twitter? Lame.
Feb 7th
I’m thinking of removing my twitters from my Tumblr blog
Feb 7th
Hanging with Brooke Paul, talking Security Start Up
Feb 7th
Beaker - You don’t count. You’re an outlier.
Feb 7th
hi I’m a cso. How are you going to help me manage my risk much better than I am today?
Feb 7th
LOL andy. Youre the majority of the distribution
Feb 7th
I’m sore and tired and need more coffee. Newborns are fun
Feb 7th
there is no ROI in security. There is only the reduction of probabilities.
Feb 7th
Having a great meeting with a large enterprise CISO who has been using FAIR without our input and comparing notes. I’m LOVING today!
Feb 6th
It’s all about userbase. Jaiku & Pownce both seem cooler than Twitter to some degree…
Feb 6th
I’m also wondering if .NET isn’t in my future
Feb 6th
Google Reader not marking things as “read”. Never thought netnewswire would be better…
Feb 6th
I’m going to bed. I’ve had it with today
Feb 6th
yeah! The baby is *very* cholicy
Feb 6th
Writing a response to the ISO 27001 mailing list. Hoping that I can communicate effectively between languages and skill sets represented.
Feb 5th
Everybody else is having a great day, and I can’t figure out how to subscribe to RSS in Firefox 3b2. Not my day…
Feb 4th
Apparently a refresh made the little icon come back. Oh Happy Day anyhow!
Feb 4th
Caught up with Mark for a bit. Good to hear the Microsoft thing is working out for him. He seems very happy
Feb 4th
trying pockettweets on iphone while dreameaver installs
Feb 4th
Could Twihrl be the culprit? Had complete freeze again right before it updated
Feb 4th
AppZapper for OS X Is fun…
Feb 4th
no force quit, hard reboot. Suspecting Dreamweaver
Feb 4th
Firefox Beta 3 just bit it. FORCE QUIT
Feb 4th
But he’s in a meeting now! I did leave him a VM
Feb 4th
Oh man, I just told Mortman I’d meet him downtown for lunch, and my wife took my keys. I’m stranded.
Feb 4th
Oh, I’m worried about the economy. Worried about the economy. If this isn’t handled right, it could be a serious recession.
Feb 4th
Looking for Old VPN Manuals →
Happy Monday!   I’m looking for old VPN manuals, sales brochures, or other documentation.   Especially old VPN-1 or Aventail MobileVPN - circa 1996/early 1997.  Might be willing to buy them.  If you have anything, please leave me a comment. Thanks, Alex
Feb 4th
If there’s a smile on my face, it’s only there tryin’ to fool the public…
Feb 2nd
Twitter IM is back, but the updates aren’t
Feb 2nd
Twitter IM is back!
Feb 1st
Been summoned to go procure dinner. Clapping twice to turn twitter off.
Feb 1st
Trying out CSSEdit & Pixelmator for some web work. LOOKIT ME, I’m going Delicious!
Feb 1st
Hooray For Humanity http://tinyurl.com/37mlh5
Feb 1st
IRM friend of mine finding out that manufacturing is different from Financial Servcies.
Feb 1st
SecurityTwitters: You’re impression of BiTS please!
Feb 1st