« Pie on My Face | Main | Spire's Second Law of Internet Dynamics »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345207f669e200e5507189e88834

Listed below are links to weblogs that reference On Value and Loss:

» Ignore What's Hard to Measure? from Perilocity
But IT security generally doesn't have the economic part worked out. With quantification of value and probable loss we'd have better risk management. [Read More]

Comments

Your criticism is FAIR enough (sorry, couldn't resist). I actually have not offered an alternative.

I believe the alternative lies in processes, not assets.

But measuring the value of a process, unless you've got some hot shot consulting company (*cough*) is problematic.

Hopefully someone will figure it all out and distribute the answer using some open or semi-open license.

Been following the draft work for ISO 27004? It's all about setting an international standard for infosec measurements. Essentially, layering on top of 27001 system for managing controls (controls being in 17799). Lotsa tough math in there... but I see that as a good thing.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment