<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.ism-community.org/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Risk Management Blog</title><subtitle type="html" /><id>http://www.ism-community.org/blogs/riskmanagementblog/atom.aspx</id><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/riskmanagementblog/default.aspx" /><link rel="self" type="application/atom+xml" href="http://www.ism-community.org/blogs/riskmanagementblog/atom.aspx" /><generator uri="http://communityserver.org" version="3.0.20423.869">Community Server</generator><updated>2007-05-02T11:50:00Z</updated><entry><title>Risk Assessment Methodology Update</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/07/11/risk-assessment-methodology-update.aspx" /><id>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/07/11/risk-assessment-methodology-update.aspx</id><published>2007-07-11T11:28:00Z</published><updated>2007-07-11T11:28:00Z</updated><content type="html">&lt;p&gt;With a couple of volunteers, work on the RA Methodology has been moving forward.&amp;nbsp; I spent some of the last week working on the front and back of it, adding in the niceties like the license snippet, links to other risk assessment/management guides, etc.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;While I can crank out the various sections myself, I would like a couple more volunteers to help out, especially people who will &amp;quot;adopt&amp;quot; one of the following sections and commit to getting it to 75% done:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Determine Threats&lt;/li&gt;&lt;li&gt;Determine Countermeasures&lt;/li&gt;&lt;li&gt;Determine Vulnerabilities&lt;/li&gt;&lt;li&gt;Determine Risk&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;I&amp;#39;ve found that with more people working on the document, it gets a very different flavor than if there is one sole author.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Until next time&lt;/p&gt;&lt;p&gt;--Rybolov&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1037" width="1" height="1"&gt;</content><author><name>rybolov</name><uri>http://www.ism-community.org/members/rybolov.aspx</uri></author><category term="risk assessment" scheme="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+assessment/default.aspx" /></entry><entry><title>Getting Back on the Horse</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx" /><id>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx</id><published>2007-06-22T02:25:00Z</published><updated>2007-06-22T02:25:00Z</updated><content type="html">
&lt;p&gt;&amp;quot;First we said it was too cold and that the fish were not feeding.&amp;nbsp; Then we said it was too sunny and the fish were scared.&amp;nbsp; Then we discovered that the fish had gone elsewhere.&amp;nbsp; When we found the fish, we started casting to them with nice juicy baitfish flies.&amp;quot;&lt;/p&gt;
&lt;p&gt;So also is the story of the &lt;a href="http://www.ism-community.org/files/folders/riskmanagementrelease/entry743.aspx" target="_blank"&gt;ISM Community Risk Assessment Methodology&lt;/a&gt;.&amp;nbsp; After more than a few false-starts (Curphey changing the server platform, some flirtation with FAIR, almost scoring a free methodology to have and to hold, the apparent ADHD of the project lead), we are continuing down the merry path of creating our own risk assessment methodology.&lt;/p&gt;
&lt;p&gt;Now that we&amp;#39;re back to casting for trout, I would like to issue an Internet-wide call for volunteers.&amp;nbsp; What I&amp;#39;m looking for is about a dozen people who know Risk Assessment and simultaneously know how to write well.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Really the methodology consists of several parts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A document that describes the process (partially started)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;A set of artifacts to assist in the process such as inventory spreadsheets and a risk register (partially done)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Reference implementations where we take the process and test it out (not yet, we need the process first)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;References and similar projects&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Glossary&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Foo&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
I have a &lt;a href="http://www.hungryfishconsulting.com/ismcommunity/RA%20Methodology%20Status%202007%2006%2021.xls" target="_blank"&gt;handy-dandy spreadsheet to track status&lt;/a&gt;.&amp;nbsp; If you are interested in helping out, go to the RA forum at &lt;a href="http://www.ism-community.org/forums/t/564.aspx" target="_blank"&gt;http://www.ism-community.org/forums/t/564.aspx&lt;/a&gt; (it&amp;#39;s broken right now, I tried to upload the spreadsheet and it bombed out on me) or shoot me an email with a description of what you would like to help out with.&lt;/p&gt;
&lt;p&gt;Cheers&lt;br /&gt;
--Mike&lt;br /&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=965" width="1" height="1"&gt;</content><author><name>rybolov</name><uri>http://www.ism-community.org/members/rybolov.aspx</uri></author><category term="risk assessment" scheme="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+assessment/default.aspx" /><category term="risk management" scheme="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+management/default.aspx" /><category term="ism-community" scheme="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/ism-community/default.aspx" /></entry><entry><title>State of Risk Management in ISM-Community</title><link rel="alternate" type="text/html" href="http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx" /><id>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx</id><published>2007-05-02T15:50:00Z</published><updated>2007-05-02T15:50:00Z</updated><content type="html">&lt;p&gt;ISM-Community was originally created and the steering committee formed in Fall of 2006.&amp;nbsp; During that time, one of our key activities was to come up with a list of projects that were worthwhile, and that list became somewhat of a direction for us to move in.&lt;/p&gt;&lt;p&gt;One of the first priorities has been to develop a risk assessment methodology.&amp;nbsp; Me being of a US Government mindset, my first question was &amp;quot;What&amp;#39;s wrong with NIST SP 800-30?&amp;quot;&amp;nbsp; Well, 800-30 is a good start, but like I&amp;#39;ve said before, there are some things such as templates, examples, and suggestions that NIST can&amp;#39;t give you because then all the auditors take it as gospel/doctrine instead of implementation technique.&amp;nbsp; We want to bridge that gap.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;We traveled down the RA Methodology road over the past 6 months or so and due to a handful of factors, mostly time constraints (find me a security person worth anything at all and they&amp;#39;re up to their eyeballs in projects) and a couple of false paths we&amp;#39;ve gone down (FAIR was a good one, but we had a philosophy/licensing issue), the project has stuttered.&lt;/p&gt;&lt;p&gt;What remains to be done?&amp;nbsp; Well, this is my roadmap for the near- to moderate-term future:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Finish off the remaining RA Methodology sections&lt;/li&gt;&lt;li&gt;Creation of artifacts/templates/examples to support the methodology&lt;br /&gt; &lt;/li&gt;&lt;li&gt;Field-testing to validate the methodology&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;At some point, the artifacts will suffer from scope-creep as they become a set of ISM .&amp;nbsp; That&amp;#39;s OK.&lt;br /&gt;&lt;p&gt;In true NPO form, I&amp;#39;m asking for volunteers who can help out.&amp;nbsp; The first step is to look at the &lt;a href="http://www.ism-community.org/files/folders/riskmanagementrelease/entry743.aspx" target="_blank"&gt;existing incarnation of the RA Methodology&lt;/a&gt; and make recommendations.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=793" width="1" height="1"&gt;</content><author><name>rybolov</name><uri>http://www.ism-community.org/members/rybolov.aspx</uri></author></entry></feed>