<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.ism-community.org/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Risk Management Blog - All Comments</title><link>http://www.ism-community.org/blogs/riskmanagementblog/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2007 (Build: 20423.869)</generator><item><title>re: Getting Back on the Horse</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx#1072</link><pubDate>Sat, 22 May 2010 21:56:11 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1072</guid><dc:creator>janko</dc:creator><description>&lt;p&gt;It is good you are back on the horse! hh: )&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1072" width="1" height="1"&gt;</description></item><item><title>re: Risk Assessment Methodology Update</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/07/11/risk-assessment-methodology-update.aspx#1062</link><pubDate>Tue, 02 Dec 2008 15:09:05 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:1062</guid><dc:creator>ebellis</dc:creator><description>&lt;p&gt;Any thoughts of getting this back up and running? The content is getting a little stale,I'd be happy to help out where I can.&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=1062" width="1" height="1"&gt;</description></item><item><title>re: State of Risk Management in ISM-Community</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx#978</link><pubDate>Sat, 23 Jun 2007 00:11:58 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:978</guid><dc:creator>rybolov</dc:creator><description>&lt;p&gt;Yes sir. &amp;nbsp;There are many ways to &amp;quot;skin a cat&amp;quot; but basically most risk management methodologies are the same at the core. =)&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=978" width="1" height="1"&gt;</description></item><item><title>re: State of Risk Management in ISM-Community</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx#977</link><pubDate>Fri, 22 Jun 2007 20:12:14 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:977</guid><dc:creator>erichnewell</dc:creator><description>&lt;p&gt;So as to not re-invent the wheel, be sure to look at the IAM and IEM produced by the NSA.&lt;/p&gt;
&lt;p&gt;Developed in 1998, the National Security Agency INFOSEC Assessment Methodology is pretty robust and still relevant. The book &amp;lt;i&amp;gt;&amp;quot;Security Assessment: Case Studies for Implementing the NSA IAM&amp;quot;&amp;lt;/i&amp;gt; covers the NSA IAM in a logical progression and draws from 800-30 among others.&lt;/p&gt;
&lt;p&gt;I recommend it highly along with the NSA IEM as well.&lt;/p&gt;
&lt;p&gt;Drawing from these to bodies should go a long way towards development of a heuristic methodology.&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=977" width="1" height="1"&gt;</description></item><item><title>ISM RA Methodology &amp;laquo; Mark Curphey - SecurityBuddha.com</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx#973</link><pubDate>Fri, 22 Jun 2007 05:49:13 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:973</guid><dc:creator>ISM RA Methodology « Mark Curphey - SecurityBuddha.com</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;ISM RA Methodology &amp;amp;laquo; Mark Curphey - SecurityBuddha.com&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=973" width="1" height="1"&gt;</description></item><item><title>re: Getting Back on the Horse</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx#971</link><pubDate>Fri, 22 Jun 2007 05:44:42 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:971</guid><dc:creator>mcurphey</dc:creator><description>&lt;p&gt;File upload works. It was your user error ;-)&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=971" width="1" height="1"&gt;</description></item><item><title>The Guerilla CISO  &amp;raquo; Blog Archive   &amp;raquo; Call for Volunteers</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/06/21/getting-back-on-the-horse.aspx#966</link><pubDate>Fri, 22 Jun 2007 02:51:26 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:966</guid><dc:creator>The Guerilla CISO  » Blog Archive   » Call for Volunteers</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;The Guerilla CISO &amp;nbsp;&amp;amp;raquo; Blog Archive &amp;nbsp; &amp;amp;raquo; Call for Volunteers&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=966" width="1" height="1"&gt;</description></item><item><title>re: State of Risk Management in ISM-Community</title><link>http://www.ism-community.org/blogs/riskmanagementblog/archive/2007/05/02/state-of-risk-management-in-ism-community.aspx#795</link><pubDate>Wed, 02 May 2007 16:54:35 GMT</pubDate><guid isPermaLink="false">b96df89b-40a7-4829-bad0-5e17a7c202b4:795</guid><dc:creator>mcurphey</dc:creator><description>&lt;p&gt;Superb Monsieur Guerilla.&lt;/p&gt;
&lt;p&gt;I think you are spot on about the lack of simple tools to support RA.&lt;/p&gt;
&lt;p&gt;Also it may be worth us digging up the list we came uo with of the Current Issues with RA. If I recall there was a uninimous vote for something that was super fast and reasonably accurate (qualitative) rather than something that took a while to compute and was better.&lt;/p&gt;
&lt;img src="http://www.ism-community.org/aggbug.aspx?PostID=795" width="1" height="1"&gt;</description></item></channel></rss>