Posted in COBIT, Forensics, ISACA, NIST, SANS, To Do on Apr 29th, 2007
“She is too fond of books, and it has turned her brain.” — Louisa May Alcott
I wanted to post a few more references. Hopefully, I will even find time to read these documents. I have referenced many times in this blog various NIST SP documents. On Friday, they published a guide to [...]
Read Full Post »
Posted in Forensics, To Do on Apr 29th, 2007
“Doubt comes in at the window when inquiry is denied at the door.”
– Benjamin Jowett
I wanted to post a few more references in the area of forensics. There is a new book coming out, “Windows Forensic Analysis.” It is written by Harlan Carvey, who is also a member of the Security Catalyst Community [...]
Read Full Post »
Posted in Metrics, To Do on Apr 29th, 2007
“The purpose of risk management is to improve the future, not to explain the past. Security metrics are the servants of risk management, and risk management is about making decisions under uncertainty. Therefore, the only security metrics we are interested in are those that support decision making about risk for the purpose of managing [...]
Read Full Post »