Infosec's inability to quantify risk
blog.erratasec.com
Infosec's inability to quantify risk
1–10 of 54 posts
Re: Infosec's inability to quantify risk
#2What tripe.
Re: Infosec's inability to quantify risk
#3"Risk is binary, either there is risk or there isn't." What tripe.
>Infosec isn't a real profession. Among the things missing is proper "risk analysis". Instead of quantifying risk, we treat it as an absolute. Risk is binary, either there is risk or there isn't. We respond to risk emotionally rather than rationally, claiming all risk needs to be removed. This is why nobody listens to us. Business leaders quantify and prioritize risk, but we don't, so our useless advice is ignored.
Re: Infosec's inability to quantify risk
#4"Risk is binary, either there is risk or there isn't." What tripe.
Re: Infosec's inability to quantify risk
#5Where we do have a problem, and it's an industry-wide problem, is that there is no real widely applicable methodology for evaluating and quantifying security risk. There are lots of risk assessment methodologies, but all of the ones we've tried still leave you making subjective decisions and best-guesses.
Re: Infosec's inability to quantify risk
#6The difference between a software hack and bad driving is one of responsibility for the risks we face. When people are negligent, we humans like to see people taking responsibility and facing justice. This is why the Jeeps have been recalled: the manufacturer is taking responsibility. Sloppy driving is also transient and hard to predict. It occurs when drivers are stressed, fatigued or distracted. Software flaws are just there. They can be triggered maliciously on-demand.
Debating whether self-driving cars are OK, because, hey, they will probably save more lives than they will take gives me chills. What about the emotional detachment this brings? Who will be responsible for these deaths?
I'm not exactly sure what I'm trying to put my finger on. It's not so much our inability to calculate probabilities and run statistical models. This is about something more sociological than that.
Re: Infosec's inability to quantify risk
#7Re: Infosec's inability to quantify risk
#8This disturbs me. Basically I think he's saying we should accept flawed and unproven technologies in the name of progress because "eh, any new risk is small compared to the risks we already face anyways". The difference between a software hack and bad driving is one of responsibility for the risks we face. When people are negligent, we humans like to see people taking responsibility and facing justice. This is why th…
Re: Infosec's inability to quantify risk
#9This seems to be borne out by the arguments about, say, the speed of disclosure vs patching. There is no agreement, and seemingly no desire to quantify the risk and danger of different types of flaw, different strategies for patching them, different disclosure schedules, etc. So, from my layperson's view, it seems like a wild west where the person who shouts the loudest, or acts the most obnoxiously, wins the argument. Cheered on by others who claim that such behavior is optimal overall. As an engineering discipline, it is rather mystifying, imho.
Re: Infosec's inability to quantify risk
#10Yes, Charlie Miller and Chris Valasek's stunt had relatively low risk, but the difference is that they were risking the lives of innocent people who had nothing to do with it. You don't get to "quantify risk" for others who didn't ask for it, who are completely unassociated with you and your activities.
"Business leaders quantify and prioritize risk, but we don't, so our useless advice is ignored."
I do agree that progress needs to be made on this front.