A Hacker's Guide to Risk [pdf]
media.defcon.org
media.defcon.org
perhaps the title could include an adjective which specifies the type of risk under consideration.
OP: might I recommend adding a DEFCON: tag to the beginning of the title?
I found the following by perusing the first few search results for obvious search terms:
http://www.quora.com/What-is-a-good-strategy-for-Risk-the-bo...
It might be a good start at answering the questions raised here...
Spot on that the security industry (and IMHO many internal security departments) often focusing on technical vs. business risk. Who needs risk management when you have fancy sound bites and scary sounding technical jargon?
Pedantic nitpick: Death statistics slide asks 'what could a billion $ do for these causes?' The question is more... what would Takata / Honda have done with the time and resources from the outcome.
Cheers!
Ethically though I think the recall was the right thing to do. And presumably the sooner they do it the better for everyone?
Another interesting 'risk' to look at is given some evidence that your product may be defective, what is the probability that is actually is defective (upon further tests). And whether to test 'under the radar' or be transparent about the problem. (Putting ethics to one side for a moment).
Vulnerabilities: - We buy our servers from an Iranian on eBay
I've got two questions for the creator of these slides (Bruce Potter):
1) When was the last time you found an Iranian selling servers on eBay?
2) Where do people come up with this kind of generalization for any country?
I.e. how much should I and my manager worry about a given vulnerability, and how do I balance addressing vulns with the core business need to serve customers?
Probability is more of a distraction. Probably.
The problem with applying this to IT security is that I see no way to lower the impact. With hard drives, we use RAID to build a more resilient system from unreliable components. It seems harder to do that with the concept of customer passwords, credit card numbers and SSNs and still have a system the accountants can use to reliably file earnings reports.
My guesses are that he was saying the security community regularly freaks out about small things like complex MiTM attacks which if you followed these frameworks for Risk and Threats he has laid out you'd realize are not that big of a deal. At least not the big deal that they were on twitter, blogs, etc. He's basically saying stop crying wolf, use the risk management tools to figure out if this is actually a big deal and if it is THEN freak out. If they do this then when they freak out at the right moments the community will be more respected for their freak outs and people will respond to any problems raised..
Oftentimes people get hung up in fixing or doing things that are important to do for security, but not a pressing matter, and they may miss more important issues because of this.
There are a lot of security folk who worry about things that make very little difference and it not only makes me think less of them but it also is more noise and less signal. It means businesses have a harder time taking security people seriously whenany constantly worry about the wrong things.
I have never before seen a discussion on risk management that didn't start by drawing out that quadrant.