<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.ism-community.org/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Risk Management Blog</title><link>http://www.ism-community.org/blogs/riskmanagementblog/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2007 (Build: 20423.869)</generator><item><title>Risk Assessment Methodology Update</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/07/11/risk-assessment-methodology-update.aspx</link><pubDate>Wed, 11 Jul 2007 11:28:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1037</guid><dc:creator>rybolov</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.ism-community.org/blogs/riskmanagementblog/rsscomments.aspx?PostID=1037</wfw:commentRss><comments>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/07/11/risk-assessment-methodology-update.aspx#comments</comments><description>&lt;p&gt;With a couple of volunteers, work on the RA Methodology has been moving forward.&amp;nbsp; I spent some of the last week working on the front and back of it, adding in the niceties like the license snippet, links to other risk assessment/management guides, etc.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;While I can crank out the various sections myself, I would like a couple more volunteers to help out, especially people who will &amp;quot;adopt&amp;quot; one of the following sections and commit to getting it to 75% done:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Determine Threats&lt;/li&gt;&lt;li&gt;Determine Countermeasures&lt;/li&gt;&lt;li&gt;Determine Vulnerabilities&lt;/li&gt;&lt;li&gt;Determine Risk&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;I&amp;#39;ve found that with more people working on the document, it gets a very different flavor than if there is one sole author.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Until next time&lt;/p&gt;&lt;p&gt;--Rybolov&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1037" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+assessment/default.aspx">risk assessment</category></item><item><title>Getting Back on the Horse</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx</link><pubDate>Fri, 22 Jun 2007 02:25:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:965</guid><dc:creator>rybolov</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.ism-community.org/blogs/riskmanagementblog/rsscomments.aspx?PostID=965</wfw:commentRss><comments>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx#comments</comments><description>
&lt;p&gt;&amp;quot;First we said it was too cold and that the fish were not feeding.&amp;nbsp; Then we said it was too sunny and the fish were scared.&amp;nbsp; Then we discovered that the fish had gone elsewhere.&amp;nbsp; When we found the fish, we started casting to them with nice juicy baitfish flies.&amp;quot;&lt;/p&gt;
&lt;p&gt;So also is the story of the &lt;a href="http://www.ism-community.org/files/folders/riskmanagementrelease/entry743.aspx" target="_blank"&gt;ISM Community Risk Assessment Methodology&lt;/a&gt;.&amp;nbsp; After more than a few false-starts (Curphey changing the server platform, some flirtation with FAIR, almost scoring a free methodology to have and to hold, the apparent ADHD of the project lead), we are continuing down the merry path of creating our own risk assessment methodology.&lt;/p&gt;
&lt;p&gt;Now that we&amp;#39;re back to casting for trout, I would like to issue an Internet-wide call for volunteers.&amp;nbsp; What I&amp;#39;m looking for is about a dozen people who know Risk Assessment and simultaneously know how to write well.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Really the methodology consists of several parts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A document that describes the process (partially started)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;A set of artifacts to assist in the process such as inventory spreadsheets and a risk register (partially done)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;Reference implementations where we take the process and test it out (not yet, we need the process first)&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;References and similar projects&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Glossary&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Foo&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
I have a &lt;a href="http://www.hungryfishconsulting.com/ismcommunity/RA%20Methodology%20Status%202007%2006%2021.xls" target="_blank"&gt;handy-dandy spreadsheet to track status&lt;/a&gt;.&amp;nbsp; If you are interested in helping out, go to the RA forum at &lt;a href="http://www.ism-community.org/forums/t/564.aspx" target="_blank"&gt;http://www.ism-community.org/forums/t/564.aspx&lt;/a&gt; (it&amp;#39;s broken right now, I tried to upload the spreadsheet and it bombed out on me) or shoot me an email with a description of what you would like to help out with.&lt;/p&gt;
&lt;p&gt;Cheers&lt;br /&gt;
--Mike&lt;br /&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=965" width="1" height="1"&gt;</description><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+assessment/default.aspx">risk assessment</category><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.ism-community.org/blogs/riskmanagementblog/archive/tags/ism-community/default.aspx">ism-community</category></item><item><title>State of Risk Management in ISM-Community</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx</link><pubDate>Wed, 02 May 2007 15:50:00 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:793</guid><dc:creator>rybolov</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.ism-community.org/blogs/riskmanagementblog/rsscomments.aspx?PostID=793</wfw:commentRss><comments>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx#comments</comments><description>&lt;p&gt;ISM-Community was originally created and the steering committee formed in Fall of 2006.&amp;nbsp; During that time, one of our key activities was to come up with a list of projects that were worthwhile, and that list became somewhat of a direction for us to move in.&lt;/p&gt;&lt;p&gt;One of the first priorities has been to develop a risk assessment methodology.&amp;nbsp; Me being of a US Government mindset, my first question was &amp;quot;What&amp;#39;s wrong with NIST SP 800-30?&amp;quot;&amp;nbsp; Well, 800-30 is a good start, but like I&amp;#39;ve said before, there are some things such as templates, examples, and suggestions that NIST can&amp;#39;t give you because then all the auditors take it as gospel/doctrine instead of implementation technique.&amp;nbsp; We want to bridge that gap.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;We traveled down the RA Methodology road over the past 6 months or so and due to a handful of factors, mostly time constraints (find me a security person worth anything at all and they&amp;#39;re up to their eyeballs in projects) and a couple of false paths we&amp;#39;ve gone down (FAIR was a good one, but we had a philosophy/licensing issue), the project has stuttered.&lt;/p&gt;&lt;p&gt;What remains to be done?&amp;nbsp; Well, this is my roadmap for the near- to moderate-term future:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Finish off the remaining RA Methodology sections&lt;/li&gt;&lt;li&gt;Creation of artifacts/templates/examples to support the methodology&lt;br /&gt; &lt;/li&gt;&lt;li&gt;Field-testing to validate the methodology&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;At some point, the artifacts will suffer from scope-creep as they become a set of ISM .&amp;nbsp; That&amp;#39;s OK.&lt;br /&gt;&lt;p&gt;In true NPO form, I&amp;#39;m asking for volunteers who can help out.&amp;nbsp; The first step is to look at the &lt;a href="http://www.ism-community.org/files/folders/riskmanagementrelease/entry743.aspx" target="_blank"&gt;existing incarnation of the RA Methodology&lt;/a&gt; and make recommendations.&lt;/p&gt;&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=793" width="1" height="1"&gt;</description></item></channel></rss>