4 ms·
1. Start thinking in terms of accepted risk. What is accepted risk? It's risk that you, evryone at the company, and its stakeholders are willing to accept failu
by aliswe 4y ago
1. Start thinking in terms of accepted risk. What is accepted risk? It's risk that you, evryone at the company, and its stakeholders are willing to accept failure because of.
For example, going out to buy milk at 3am inabrough neighborhood might not be accepted risk - the risk vs value is off.
To buy diapers in a 3am emergency? Yup.
To drive a car on the motorway is hella dangerous. Super risky when you think about it. But you can't not do it. (presumably/ So what do you do? You check your brakes, indicators, steering, etc bfore taking off. Get it to periodical checkups.
Then if it fails, you did your part, you did what you could. It's accepted risk.
It's at the point when you go "well, if I'm not gonna do that then I might as well stay in bed all day". You could get hit by a meteor going out your door you know.
If you declare something an accepted risk, accept no blame for it failing. it was accepted risk. not your falt that it happened, but it was you who decided that its accepted risk. It was your decision (but inform everyone). If you dont want to stand for the decision, defer it, or maybe you're in the wrong spot.
2. Then there is the concept of unknown unknowns. Talk to everybody in the company, make sure that noone sits on a domain or problem area you are totally unaware of. Survey/canvas the landscape, and report back to your superiors. Then drill down wherever necessary
- hbrn 4y agoThis. Security is one of those things everybody thinks you can't have too much of. But of course you can. You can literally kill your company if you start blindly implementing "best practices". It's very easy to fall into threat prevention trap, but what you should be thinking about is risk tolerance.