Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Laptop Losses and Phishing Fruit Salad
Dr. Neal Krawetz, 2007-02-15

Dr. Neal Krawetz takes a look at the numbers behind reports of laptop thefts and phishing attacks, showing inconsistent metrics and the difficulty in using numbers to determine the real level of threat.

Comments Mode:
Laptop Losses and Phishing Fruit Salad 2007-02-16
Anonymous (2 replies)
Re: Laptop Losses and Phishing Fruit Salad 2007-02-19
Ben
Additionally, as budgets for security controls are limited, one would have to prioritize risks to mitigate the most important threats first and leave less endangered assets for later. Assurance companies can provide extremely valuable data that can be used as input in these risk assessments. Unfortunately they only have data for a limited amount of threats. To make IT security management more objective and reduce the guessing, we need more hard numbers that we can use in quantitative risk assessment. This is not the assurance company?s problem on the short term, it?s ours.

PS: Great article, you hit the nail on the head!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/435/34363#34363







 

Privacy Statement
Copyright 2009, SecurityFocus