Disclosure of risk is an ethical dilemma

Posted by jericho Wed, 05 Oct 2005 07:13:13 GMT

http://news.ft.com/cms/s/48307322-28d9-11da-8a5e-00000e2511c8.html

Disclosure of risk is an ethical dilemma Published: September 20 2005 16:54 | Last updated: September 20 2005 16:54

When Donald Rumsfeld spoke of “known knowns”, “known unknowns” and “unknown unknowns” the world laughed. But the concepts he outlined are familiar to risk managers.

Computer security knowns and unknowns correspond to risks within systems. A risk exists when a system has a vulnerability and a mechanism exists to exploit it.

Vulnerabilities that can be exploited are quantifiable risks (known knowns), while for those for which there is no exploitation (known unknowns) the impact is unquantifiable.

[..]

Posted in  | no comments

Comments

(leave url/email »)

   Comment Markup Help Preview comment