3 ms·
This seems like applying insurance modeling to security. Is this a new way of looking at risk or a reinvention?
by rubyfan 7y ago
This seems like applying insurance modeling to security. Is this a new way of looking at risk or a reinvention?
- im_down_w_otp 7y agoLooks like parts of FMEA w/ some specific measurements to inform occurance & severity.
- Eridrus 7y agoThis is part of an attempt to make information security risk modelling more quantitative that has been going on for a few years. There's very little in the way of data to really back most of this up, but actually putting numbers to things is significant progress IMO.
- rubyfan 7y agoAgree it seems like a better way to inform decisions and manage risk. Is it backed by any sort of real understanding of litigation, settlement, statutory experience? I often hear reputational risk cited by security teams at public companies... it usually follows some sort of indecision or appeal to a higher level of management or beuqacratic tool.
- Eridrus 7y agoNot really. But it's significant progress compared to sticking charts like this into reports https://www.shipownersclub.com/media/2017/02/Risk-matrix-1-768x386.png https://www.shipownersclub.com/media/2017/02/Risk-matrix-1-7... I think it's also worth saying that when people say reputational risk they're generally not thinking about litigation, they're thinking about consumer perception, which it's not crazy to believe would have large impacts for large companies.
- TeMPOraL 7y agoNeither; the idea has been around for many years now (source: worked professionally on exactly these calculations this library does, in the same space). It's just basic probability theory and Monte Carlo simulations; nothing anywhere near as complex as the quants/insurance folks do. IME, the biggest problem in this space is: on the one side, you have all kinds of metrics related to hardware, software and operations in your company; on the other side, you have FAIR and related ideas that let you model scenarios in a sane way, and let you plug in those statistical methods. But, there's no good idea how to connect these two sides. There is a vast gulf between what you can reliably and accurately measure, and what you actually want to know. It's hard to cross it while maintaining any kind of accuracy or statistical validity. I've been doing work on this "middle layer", but never got the chance to test it out in the open, as the company I worked for suddenly imploded. (If anyone is working in this space and is accepting remote workers, I'm available for a chat.)