3 ms·
An inability to quantify risk is attributing a skill set to an industry which is probably not responsible for quantifying risk. Infosec researchers should only
by sprkyco 11y ago
An inability to quantify risk is attributing a skill set to an industry which is probably not responsible for quantifying risk. Infosec researchers should only be beholden to identifying and detailing risks. There are infosec subsets that require better skills to identify risks, but those subsets are the one's more responsible for quantifying risk in an appropriate manner not the ENTIRE industry.
Quantifying risk is a very difficult endeavor to do properly so any measure of it is done from the security researchers biased perspective. Yes infosec researchers seem to want attention for their work this is often because there is not near enough attention paid to their work. Actuarial science is an entire professional field specifically tasked with quantifying risk, at least from an insurance perspective.
The inferred statement, at least in the title, is that not only do infosec researchers now have to stay up on crypto, assembly, js[buzzword] framework and on and on, but now they must also become actuarial scientists. As a neophyte in the industry I'm having trouble getting caught up to a static point let alone that the static point is a moving and rapidly accelerating target and not in my favor. Adding to this unachievable standard I now must study and become at least somewhat proficient in actuarial sciences is maddening!
- blincoln 11y agoI completely agree. To make things worse, I'm not even sure that it's practical to use an actuarial approach in a way that will produce remotely valid results. Actuaries based calculations of probability on past occurrences. This is why car insurance is calculated using a huge variety of variables like age of the driver, make/model of the car, etc. So first of all, where is the data about past compromises going to come from? Just about no organization is willing to share it unless there is a legal requirement to do so. Unless something dramatic changes, that means only the most high-profile events from other organizations will become part of the pool of data to work with. More importantly, however, IMO there are far too many variables in order to do anything meaningful with that data. When the exploitability of a particular vulnerability can depend on everything from the specific type of hardware the OS hosting the app is hosted on, to the choice of database back-end, so a single configuration setting in an XML or other type of file, how is that even trackable, let alone something that can be calculated with any sort of accuracy?