in

What RA method is "good enough" for the GLBA examiners?

Last post 07-30-2007 6:24 PM by mcurphey. 2 replies.
Page 1 of 1 (3 items)
Sort Posts: Previous Next
  • 07-23-2007 12:54 PM

    • mcurphey
    • Top 10 Contributor
    • Joined on 02-13-2007
    • Europe
    • Posts 199
    • Points 2,130

    What RA method is "good enough" for the GLBA examiners?

    http://news.google.com/news/url?sa=T&ct=us/1-0&fd=R&url=http://www.pr.com/press-release/46019&cid=0&ei=n9qkRoOaN4P20QGjpcnvCg

    I read this with interest and have to ask myself, what RA methodology is "good enough"?

    • Post Points: 40
  • 07-23-2007 2:50 PM In reply to

    • halon73
    • Top 25 Contributor
    • Joined on 02-16-2007
    • Broomfield, CO
    • Posts 4
    • Points 65

    Re: What RA method is "good enough" for the GLBA examiners?

    How can the weather be “compliant” with a law or regulation?   The fundamental flaw with all “compliance” regulations is the measurements that are used to assess “the weather” and more importantly the output of those assessments.   The weather changes from moment to moment and so does risk of breaching the organizations security goals.  Neither meteorology or risk management is an exact science until you hear the drops of rain on the window and say “It’s raining” but unfortunately by that time the flash flood has taken out the town. 

     

    Paul Zedeck | Security Engineer
    Information Security Consulting & Architecture
    http://www.linkedin.com/in/zedeck
    Filed under: ,
    • Post Points: 40
  • 07-30-2007 6:24 PM In reply to

    • mcurphey
    • Top 10 Contributor
    • Joined on 02-13-2007
    • Europe
    • Posts 199
    • Points 2,130

    Re: What RA method is "good enough" for the GLBA examiners?

    I still snigger at Dilberts "You can't spell compliance without liance"....gets me each time!

    • Post Points: 25
Page 1 of 1 (3 items)
All Rights Reserved - The ISM-Community
Powered by Community Server (Commercial Edition), by Telligent Systems