RSA Conference 2012: Risk management in the enterprise faces

  Most types of management are risk management, was one of a number of points of discussion at the Risk Management Smackdown II panel at the RSA Conference 2012 in San Francisco this week.

  The panel's subtitle, The Wrath of Kuhn, referred to philosopher Thomas Kuhn, who speaks of “proto-science,” somewhat random fact gathering (mainly of readily available data), which he terms a form of philosophical speculation that provides little guidance to data-gathering practitioners.

  The freewheeling discussion among the panelists, taking off from there and prompted by questions from the audience, hovered around issues of balancing the scientific element of data gathering with the art of interpreting the information gathered from assessments, and examined some of the challenges risk managers face – from getting executive buy-in to assuring that new products are secure.

  The panel consisted of David Mortman, chief security architect at enStratus; Allison Miller, director of security and risk management at Tagged; Alex Hutton, director of risk at a financial institution; Andy Ellis, CSO at Akamai Technologies; and Bob Blakley, VP, distinguished analyst and agenda manager for Gartner.

  In opening statements, Miller said that at her former job at a financial institution she focused on protecting user accounts, while in her new position at a social media operation her focus was more targeted at using pattern recognition and problem solving to make sense of complex systems. But, she added, “most types of management are risk management.”

  Hutton said his work focuses primarily on audit and the data science, while Ellis said he teaches people about risk, but that is only half of the recipe. The other part involves calculating for unforeseen events. This is where a balance between the science of data gathering and the art of interpretation must be forged, he said.

  Meanwhile, Blakley, in a full devil costume, spoke, literally, as a devil's advocate. “There's a lot of talk about how risk is bad,” he said. But, risk management is, in fact, evil and the enemy of security, he said in his devil guise, because it forces metrics to be applied after the fact, calculations that can often get in the way of implementing a security strategy that addresses more than patching a master list of vulnerabilities that have already been proven exploitable. “Compliance is one of my greatest inventions,” Blakley (as the devil) said.

  When an audience member asked, "How do you defend against something you don't understand," Hutton answered that people have a level of risk tolerance that can be increased if they are made to believe they have been made more secure via a new strategy, policy or tool.

  As to the challenge of how security staff can work better with people in charge of risk, a good number of those in the audience said they serve both roles.

  But, there are a number of other tasks that remain to be resolved. “We need to know how to skate to where the puck is going to be,” said Hutton.

  The good news, said Miller, is that a maturing process is occurring a more and more data that can be used to build more accurate models of risk is assembled.

  Effective risk modeling can be used to defend enterprises effectively, if done carefully, added Hutton.

  The bottom line: “Businesses care about risk,” Ellis said.

(责任编辑:)

分享到:

更多
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
  • 微笑/wx
  • 撇嘴/pz
  • 抓狂/zk
  • 流汗/lh
  • 大兵/db
  • 奋斗/fd
  • 疑问/yw
  • 晕/y
  • 偷笑/wx
  • 可爱/ka
  • 傲慢/am
  • 惊恐/jk
用户名: 验证码:点击我更换图片
资料下载专区
图文资讯

英国官员:让华为参与英国5G建设风险可控

英国官员:让华为参与英国5G建设风险可控

2月21日,英国金融时报报道称,在布鲁塞尔发表的一次演讲中,英国信号情报机构政府通...[详细]

西媒:以色列打造网络安全“硅谷”

西媒:以色列打造网络安全“硅谷”

2月13日报道 西媒称,凭借每年超过10亿美元的企业投资,以色列已经成为全球网络安全领...[详细]

俄罗斯力推脱离互联网计划 确保应急状态下

俄罗斯力推脱离互联网计划 确保应急状态下网络安全

俄罗斯新闻机构 RosBiznesKonsalting(RBK)上周报道称:作为计划实验的一部分,当局正...[详细]

GSMA呼吁欧洲守住网络安全和网络基建供应竞

GSMA呼吁欧洲守住网络安全和网络基建供应竞争力

5G将改变欧洲公民的生活和工作方式。5G作为现有4G网络的补充,与之协同工作将比以往更...[详细]

涉嫌窃取近千政界人士信息 德国20岁黑客遭

涉嫌窃取近千政界人士信息 德国20岁黑客遭逮捕

涉嫌窃取德国近千政界人士信息的黑客落网 政府拟修法加强网络安全 德国当局8日宣布,...[详细]

返回首页 返回顶部