Posts filed under 'Risk Management'
The Road Less Traveled – Software Security from Shakespeare, Jungle Book and Nature …
What do you think Shakespeare had to say about Software Security? What does an naked motorist have to do with Confidentiality? What does the Jungle Book character Baloo have to say about Security Essentials (The Bear Bare Necessities of Life security)? What does the African Wildlife have to do with Security Concepts? What does pH have to do with Security? and more …
Continue Reading Add comment Apr 29, 2008
Application Risk Modeling @ CSI 2007
The CSI 2007 conference held in Arlington, VA from Nov 3-9 2007 was a blast. In addition to the conference session being very educational, it was a great networking event affording one the opportunity to network with the brightest minds in the industry apropos security. You can access the conference posting here.
I presented on Application Risk Modeling as an integral part of the SDLC (System or Software Development Life Cycle) introducing the Tic-TiveTM Risk Spectrum.
A preview of the presentation contents is given below.

Figure 1. The SecuRiskTM Methodology of Application Risk Modeling
Figure 2. The Tic-TiveTM Risk Spectrum. Where does your organization/company fall in this spectrum?
You can download the entire presentation by clicking on the link below.
Application Risk Modeling; An Integral Part of the SDLC – By Mano Paul
Session Abstract -
The methodology introduced in this session is designed to provide proactive risk analysis and modeling techniques for applications. It addresses obstacles experienced by security professionals due to lack of automation and objective risk modeling fundamentals. Attendees will understand how application risk management results in reducing overall risk within an enterprise and transferring risk to the appropriate business segment.
Add comment Nov 26, 2007
(ISC)2 Official CISSP Practice Exams and (ISC)2 Official SSCP Practice Exams
(ISC)² is dedicated to creating new value-added services for its prospective and more than 50,000 current members worldwide. One of the most exciting of these is studISCope, our online self-assessment tool that helps candidates assess their knowledge of the CISSP or SSCP CBK®. Together with our partner, Express Certifications – a company renowned for developing innovative testing and training techniques – (ISC)² can now maximize your learning experience and focus your study efforts more precisely along whichever information security career path you choose.
Add comment Oct 11, 2007
Ham and Ham Sandwich
While attending the Computerworld 100 Premier IT Leaders conference in March, James Dallas, CIO and SVP of Medtronic Inc., in his keynote address expressed that as a CIO, he is interested in a Ham and Ham sandwich, not a Ham and Egg sandwich in which the chicken is only participating while the pig is taking all the risk.
Extrapolating the idea to risk management within organizations, if we are to liken ‘Ham’ to IT and the Business – what are some proven methodologies that information security professionals and leaders can do to “SHARE the RISK” with the businesses they support, so that the ‘Business’ is not just participating.
Additionally, are there additionally analogies that reflect a similar scenario?
Add comment May 3, 2007
Open Parachute
What good is a parachute to a skydiver when it is not opened or fails to open? Likewise, what good are security tools/controls/processes to a company when it is not properly implemented or failed to be implemented properly?
Just purchasing more and more tools and establishing multiple security controls and processes without proper implementation may lead one to what one could call “placebo” security.
Implementing security properly would entail a thorough investigation of tools that would handle (mitigate/transfer/eliminate) risk, establishment of processes that would “enable” not “impede” the business(es) that you support, education of your personnel to want to do security because they WANT to, not because they HAVE to and a governance framework to enforce policies, standards and procedures.
So, what are we talking about – What happens when a skydiver’s parachute is not opened or fails to open …
Add comment Feb 24, 2007
