<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4482521283458453577.post3730041926455170036..comments</id><updated>2010-09-19T19:44:19.182-07:00</updated><category term='SCCM'/><category term='AES'/><category term='the force'/><category term='jedi'/><category term='risk management'/><category term='passwords'/><category term='nbnsspoof'/><category term='youngling'/><category term='diversion'/><category term='updates'/><category term='externality'/><category term='bullshit'/><category term='help'/><category term='Outlook Web Access'/><category term='OS X'/><category term='gnome'/><category term='quality assurance'/><category term='encryption'/><category term='backtrack'/><category term='risk modeling'/><category term='auditing'/><category term='nbnspoof'/><category term='sith'/><category term='metrics'/><category term='python'/><category term='rails'/><category term='contact'/><category term='pointsec'/><category term='DMCA'/><category term='script'/><category term='dark side'/><category term='data loss prevention'/><category term='lockpicking'/><category term='fde'/><category term='NPV'/><category term='Application Layer Firewall'/><category term='New School'/><category term='lightsaber'/><category term='Form 0'/><category term='snort'/><category term='black fist'/><category term='monte carlo'/><category term='linux'/><category term='Book Review'/><category term='change management'/><category term='incident response'/><category term='openbsd'/><category term='PCI'/><category term='VMWare'/><category term='form III'/><category term='relayd'/><category term='security'/><category term='information'/><category term='novell'/><category term='awkward'/><category term='padawan'/><category term='policies'/><category term='video tutorial'/><category term='jar jar binks'/><category term='forensics'/><category term='TrustedSource'/><category term='mind trick'/><category term='form II'/><category term='phishing'/><category term='copyright'/><category term='economics'/><category term='antivirus'/><category term='blogger'/><category term='unix'/><category term='mac'/><category term='R72'/><category term='event logs'/><category term='Deadly Whisper'/><category term='Sidewinder'/><category term='Ubuntu'/><category term='project management'/><category term='statistics'/><category term='google'/><title type='text'>Comments on Black Fist Security: My first risk model</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.blackfistsecurity.com/feeds/3730041926455170036/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html'/><author><name>kevin thompson</name><uri>https://profiles.google.com/107682921975811187169</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-njbZ3e90-4I/AAAAAAAAAAI/AAAAAAAAAP8/tYdzjKjLpUg/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-3757504751237276533</id><published>2010-09-19T19:44:19.182-07:00</published><updated>2010-09-19T19:44:19.182-07:00</updated><title type='text'>Sorry, Jay Jacobs here and on that last anonymous ...</title><content type='html'>Sorry, Jay Jacobs here and on that last anonymous post.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/3757504751237276533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/3757504751237276533'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284950659182#c3757504751237276533' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1522045470'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-52119951094421436</id><published>2010-09-19T19:43:11.821-07:00</published><updated>2010-09-19T19:43:11.821-07:00</updated><title type='text'>I like this model, it makes sense to me (having ju...</title><content type='html'>I like this model, it makes sense to me (having just got RiskAMP myself) and I agree with some of AThulin&amp;#39;s comments, but I think what you&amp;#39;ve created is far more useful than asking likely/unlikely type questions. &lt;br /&gt;&lt;br /&gt;While your description was a little vague, it looks like you&amp;#39;ve got a good trade off between time and accuracy.  If you wanted to get a more accurate number on &amp;quot;CAS Failure&amp;quot; you could have broken that problem into further cause and effect.  Meaning rather than ask what the probability was of failure, break down the various failure conditions, causes and probabilities of those.  But like I said, I think your approach was a good trade off between time and accuracy.  If you wanted more confidence in your results you just spend more time.  ...and that&amp;#39;s the way it should be!&lt;br /&gt;&lt;br /&gt;This has got to the best start I&amp;#39;ve seen.  Ever.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/52119951094421436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/52119951094421436'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284950591821#c52119951094421436' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1522045470'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-5834774936713317196</id><published>2010-09-14T20:08:23.515-07:00</published><updated>2010-09-14T20:08:23.515-07:00</updated><title type='text'>Oops, I mean AThulin not AHutton.</title><content type='html'>Oops, I mean AThulin not AHutton.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/5834774936713317196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/5834774936713317196'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284520103515#c5834774936713317196' title=''/><author><name>Black Fist</name><uri>http://www.blogger.com/profile/10140419541264972382</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://1.bp.blogspot.com/_7Avz7RosatI/SahhJC9qpJI/AAAAAAAAAJU/nrsRQFf6KCc/S220/fist-better.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1890104126'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-9063377372314062177</id><published>2010-09-14T20:07:45.766-07:00</published><updated>2010-09-14T20:07:45.766-07:00</updated><title type='text'>@AHutton thanks for the comment.  I&amp;#39;m sure I&amp;#...</title><content type='html'>@AHutton thanks for the comment.  I&amp;#39;m sure I&amp;#39;ll be able to work some of that into the next model I put together.&lt;br /&gt;&lt;br /&gt;After reading Hubbard&amp;#39;s first book, How to Measure Anything, I learned that an uncalibrated estimator is about 80% overconfident in some cases, so I could have set the chance of failure at 1.2% but I decided to round up to a whole number.  It is still a gut feeling expressed as a number, but that&amp;#39;s better than a gut feeling expressed as a word like medium or low.  By saying 2% we have a testable hypothesis.  If one of the four servers should fail then I know that the probability is most likely greater than 5% and my next model will be more accurate.&lt;br /&gt;&lt;br /&gt;The output of this process probably IS garbage.  Models are poor approximations of real life, but every estimate we make is based on some model.  For many of us in the security field, those models live in our head and aren&amp;#39;t open to scrutiny.  I am more willing to put my faith in this model than the one in my head and the head of the overconfident sysadmins around me.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/9063377372314062177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/9063377372314062177'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284520065766#c9063377372314062177' title=''/><author><name>Black Fist</name><uri>http://www.blogger.com/profile/10140419541264972382</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://1.bp.blogspot.com/_7Avz7RosatI/SahhJC9qpJI/AAAAAAAAAJU/nrsRQFf6KCc/S220/fist-better.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1890104126'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-6440194000402145865</id><published>2010-09-13T23:43:58.187-07:00</published><updated>2010-09-13T23:43:58.187-07:00</updated><title type='text'>Looks like @RISK requires risk estimates to a degr...</title><content type='html'>Looks like @RISK requires risk estimates to a degree that is unusual to get in infosec. For instance, I doubt that the 1% probability for Exchange server failure after applying a service pack is anything but a gut feeling expressed in numbers.&lt;br /&gt;&lt;br /&gt;Your &amp;#39;doubling&amp;#39; seems a pretty strange methodology -- if you had got 15% risk instead, would you have doubled that as well? &lt;br /&gt;&lt;br /&gt;Do you have any error estimates for the original estimate, or the subsequent doubling? &lt;br /&gt;&lt;br /&gt;If the various risk elements are not commensurable (and gut feelings usually aren&amp;#39;t), you might want to try to estimate the risk that the data you get out of this process is garbage.&lt;br /&gt;&lt;br /&gt;I find that it can be quite difficult to get even a 4-level estimate out of most IT-people (extremely unlikely, unlikely, likely, very likely), and a similar 4-level estimate of the damage. (I.e. error estimates are quite large.)&lt;br /&gt;&lt;br /&gt;Also, it&amp;#39;s one thing enumerating risks, and another to enumerate the right risks. Once you have defined the system for which you are trying to do a risk analysis, ask the right people involved with that system about the risks. IT support/helpdesk/customer support are often forgotten, yet they deal with see the effects of any failures, and even a small IT failure can mean long telephone queues for support -- which is another kind of damage.&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve worked a lot with mini-analyses: get everyone together in a room, brainstorm risks, evaluate -- i.e. place them into a 4x4 grid of probability vs damage --, decide which bins need to be addressed, and so on.  As long as you get the right people together, this tend to work quite well -- failures happen when some area of the system in question was forgotten (like helpdesk operation).  The main work is done in 6-8 hours, the documentation in another day.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/6440194000402145865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/6440194000402145865'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284446638187#c6440194000402145865' title=''/><author><name>AThulin</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1624351185'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-5446071983811626531</id><published>2010-09-11T19:21:50.594-07:00</published><updated>2010-09-11T19:21:50.594-07:00</updated><title type='text'>@jth  Sorry, @RISK is an excel add on that only wo...</title><content type='html'>@jth  Sorry, @RISK is an excel add on that only works in Windows.  I am impressed with this style of risk modelling because it&amp;#39;s pretty much impossible to create a risk model without knowing the system you&amp;#39;re trying to model.  Much like you can&amp;#39;t make a model car without learning how the parts go together.  That forced me to learn more about our email system than I knew before and I think I have a more realistic risk picture than if I just used a 50,000 foot view.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/5446071983811626531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/5446071983811626531'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284258110594#c5446071983811626531' title=''/><author><name>Black Fist</name><uri>http://www.blogger.com/profile/10140419541264972382</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://1.bp.blogspot.com/_7Avz7RosatI/SahhJC9qpJI/AAAAAAAAAJU/nrsRQFf6KCc/S220/fist-better.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1890104126'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-5659193416397396192</id><published>2010-09-11T07:48:41.520-07:00</published><updated>2010-09-11T07:48:41.520-07:00</updated><title type='text'>Seems pretty straightforward to me. I&amp;#39;d be int...</title><content type='html'>Seems pretty straightforward to me. I&amp;#39;d be interested in seeing your copy, maybe working with you on a pet project or two to see if @RISK is something worth picking up for me as well.&lt;br /&gt;&lt;br /&gt;Does that work on your mac? Or win only?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/5659193416397396192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/5659193416397396192'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1284216521520#c5659193416397396192' title=''/><author><name>jth</name><uri>http://www.blogger.com/profile/10483661198345556707</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://bp2.blogger.com/_1IfbILIh32E/SEcIC6rOgdI/AAAAAAAAAhc/E9fyWJKmB3g/S220/headshot.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1142748669'/></entry><entry><id>tag:blogger.com,1999:blog-4482521283458453577.post-2527484066360952618</id><published>2010-09-08T17:03:46.203-07:00</published><updated>2010-09-08T17:03:46.203-07:00</updated><title type='text'>Awesome.</title><content type='html'>Awesome.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/2527484066360952618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4482521283458453577/3730041926455170036/comments/default/2527484066360952618'/><link rel='alternate' type='text/html' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html?showComment=1283990626203#c2527484066360952618' title=''/><author><name>Michael Janke ' or 1=1 --</name><uri>http://www.blogger.com/profile/00357905802460949707</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04760442407271622658'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://bp2.blogger.com/_MzTxs5YYjdk/SAJvvQ0hryI/AAAAAAAAAQ0/lqiaj2S3ONc/S220/mJanke.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.blackfistsecurity.com/2010/09/my-first-risk-model.html' ref='tag:blogger.com,1999:blog-4482521283458453577.post-3730041926455170036' source='http://www.blogger.com/feeds/4482521283458453577/posts/default/3730041926455170036' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-566504464'/></entry></feed>
