-
-
BlogInfoSec.com Sponsors
-
BlogInfoSec.com Partners
Agile Security: Balancing Security with the Need for Agility written by Jeff Lowder
Decision Theory is the Foundation for Information Security Risk Management
August 18, 2010 – 6:00 am
–
Disclaimer: I originally wrote the following text as a post to a mailing list in 2005, but it still seems applicable today.
The more I read the writings of various information security professionals about information security risk analysis (ISRA), the more I’m struck by the following…
Reply to Jack Jones on the Meaning of “Risk”
July 29, 2010 – 6:00 am
–
In a recent post to his blog, Jack Jones asks, “What’s ‘a risk’ anyway?” This is a great question, especially since a lot of people working in information security seem to use the word in a variety of ways, ways that often violate common usage among risk…
The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 3)
November 5, 2008 – 6:00 am
–
As we saw in part 2 of this series, some of the traditional arguments used for distinguishing between quantitative and qualitative risk analysis (RA) are based upon dubious assumptions. Many writers assume that “quantitative” equals objective and numerical, while…
The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 2)
October 29, 2008 – 6:00 am
–
Objective vs. Subjective Approaches: Strengths and Weaknesses
As we have seen, quantitative risk analyses can be subjective and qualitative risk analyses can be objective. The purpose of this slide is to summarize and discuss some of the advantages and disadvantages of both the objective and…
The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 1)
September 4, 2008 – 6:00 am
–
Many discussions of security risk analysis methodologies mention a distinction between quantitative and qualitative risk analysis, but virtually none of those discussions clarify the distinction in a rigorous way. The purpose of this 3-part series is to clarify that distinction and then show why…