Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Proactively Managing Security Risk
Naresh Verma, Yih Huang, and Arun Sood

The information technology revolution has changed the way business is transacted, governments operate, and national defense is conducted. Protection of these systems is essential and continuous efforts to protect them have resulted in exponential growth in reported security incidents. There are threats from hackers, spies, corporate raiders, terrorists, professional criminals, and vandals -- all of whom have a vested interest and well defined objectives for challenging the technology for financial and political gain, leading to damages to the enterprise infrastructure.

Comments Mode:
Proactively Managing Security Risk 2007-11-14
BelSec
I've read this paper with great interest, however I don't feel like this way of approaching risk holds up in a corporate environment. I feel like the approach views threats only as coming from the outside while different studies have already proven that inside threats are just as, if not more, impo...

[ more ]  [ reply ]
Proactively Managing Security Risk 2008-01-04
Anonymous Coward (1 replies)
Interesting, but I think it's a case of close perhaps, but no cigar.

The SLE assumes that an attack was successful. Wherease your "exposure time" seems to reduce the probability of the above from happening, if so then I think it affects the ARO rather than the EF.

Your approach seems too nois...

[ more ]  [ reply ]
Re: Proactively Managing Security Risk 2008-01-05
premo
"Even if I thought "great, sign me up, let's get started" I'd be at a loss, what would I do next?"

This is my sentiment exactly. However, I did find this paper very interesting, and it's a "good" idea. But I don't see any way of actually "proactively" managing security risk......

[ more ]  [ reply ]
Proactively Managing Security Risk 2008-01-07
Confused
Much of this was already discussed in a book by Winn Schwartau about ten years ago....

[ more ]  [ reply ]
Proactively Managing Security Risk 2008-01-07
AnyMouse
"Since exposure time reductions will reduce the time an intruder has to do damage, the intrusion tolerance approach is likely to provide additional advantage."

While I agree that some of this is a good idea I would like a better explaination. Using the quote from the article I wonder how effectiv...

[ more ]  [ reply ]
Proactively Managing Security Risk 2008-02-01
Mr T.
I agree with most of the comments above regarding the difficult applicability of this method in a

corporate environment. In most situations, I figured out risk analysis should be kept simple to be

efficient so that it could be reviewed over and over as threats and the analysis perimeter evol...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus