This is cache of http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/266619548/rsa-impressions-1.html. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
RSA Impressions - 1
2008-04-08 14:33:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
Here is some bizarre observation: many security vendors here at RSA try to sell security by saying "latest survey shows that 67% of companies are missing the control X. Oh horror! - Buy X from us NOOOOOW" and very few sell security as "latest survey shows that 67% of companies have suffered the loss of $X via Y. Oh horror! - Buy Z from us to stop Y NOW"

So what if a control X is missing? Really? Why the f people need to care? Richard said it well here too.

And the reason there is more of the former (add missing control) and less of the later (stop loss), because they themselves don't know whether what they sell will decrease the loss ... It does suck, doesn't!

And then you meet somebody honest who sells incident response tools :-) And it has been proven that good incident response tools and practices decrease incident loss. Easy, huh?
 
 
 
 
 
 
TOP SEARCH
Expand / MinimizeClose Widget
  •  
RECENT SEARCH
Expand / Minimize
  •  
RELATED VIDEO
Expand / Minimize
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia