“The purpose of risk management is to improve the future, not to explain the past. Security metrics are the servants of risk management, and risk management is about making decisions under uncertainty. Therefore, the only security metrics we are interested in are those that support decision making about risk for the purpose of managing [...]
-
Recent Posts
- Three Open Source IDS/IPS Engines: The Setup
- FISMA Reform: Lieberman, Collins, and Carper Introduce Bill
- FedRAMP and Recent Changes Prepare Feds for Cloud Adoption
- Google Visualization: An Example Graphing NVD CVE Data
- COBIT 5 Joins Together COBIT 4.1, Risk IT, and Val IT 2.0
- OMB Says Bring on the Clouds: Frightening or Funny?
- Suricata: A Next Generation IDS/IPS Engine
- Movement on the US Cyber Command
- Soon-To-Be Classic: A Geek Christmas Story
- Santa’s Secrets Leaked
Archive
Categories
-
-
Magazines
Recent Podcasts
- 2009-08-18: Mitigating Insider Threat: New and Improved Practices
- 2009-08-19: Expanding the Use of Web 2.0 Technologies to Drive Business Value
- 2009-08-28: Who put that private cloud in my public cloud?
- 2009-08-31: FLOSS Weekly
- 2009-08-31: Ron Gula on PCI DSS compliance
- 2009-08024: Web App Security in the Cloud with Customer
- 2009-09-01: Into the Breach
- 2009-09-01: The Cloud, is it ready and secure
- 2010-01-06: Open Source SOA
- 2010-04-02: Geekonomics and the Impact of Insecure Software
- 2010-04-03: Crossing the Streams with Michael Farnum
- 2010-04-30: Open and Transparent Government
Recent Presentations
- 2009-03-17: A Virtualization & Cloud Computing Fable
- 2009-06-11:Forensic/IR Summit 2008 Archive Presentations
- 2009-06-15: HotCloud 09
- 2009-06-24: Axiis Core Functionality Video Tutorial
- 2009-07-30: Black Hat USA 2009 Conference
- 2009-08-01: Mo' Money Mo' Problems
- 2009-08-02: CSRF: Yeah, It Still Works
- 2009-08-04: Death of Anonymous Travel
- 2009-08-07: Security Content Automation Protocol and Web Application Security
- 2009-08-10: The COBIT Body of Knowledge – a Layman's View
- 2009-08-14: Back of the Napkin
- 2009-09-01: Weaponizing the Web
- 2009-09-04: The Future of the Security Industry
- 2009-09-05: Johnny Long's talk at DefCon 17
- 2009-09-08: What Would Google Do?
- 2009-09-10: Gov 2.0 Summit
- 2009-09-10: Gov 2.0 Summit Events
- 2010-01-07: Vulnerability Management Scoring Systems
Selected Papers
Standard Sites
Meta