SEARCH RESULTS
 
Showing 1-10 of 477 records
 
Expand article

Risk Preferences in Chimpanzees and Bonobos

2008-04-17 06:20:51 by schneier in Schneier on Security
 
I've already written about prospect theory, which explains how people approach risk. People tend to be risk averse when it comes to gains, and risk seeking when it comes to losses: Evolutionarily, presumably it is a better survival strategy to -- all other things being equal, of course -- accept small gains rather than risking them for larger...
 
 
 
 
 
Expand article

Making Risk Measures Agree with Accounting 100%

2006-12-26 05:27:00 by Jomni in Risk Management Quant
 
In my consulting experience, there are clients that use risk software to compliment financial reporting (accounting). Instead of being used solely by the risk department, even financial controllers use it. This is due to the current trend of making financial reporting reflective of the firm's economic value based on the risks it is taking ( IAS...
 
 
 
 
 
Expand article

The Impact of Dans DNS Debacle on Internet Risk

2008-07-30 08:11:30 by Burton Group in Security and Risk Management Strategies Blog
 
Blogger: Pete Lindstrom On July 8th, Dan Kaminsky of IOActive announced a major DNS vulnerability in conjunction with a number of major DNS vendors. The announcement was off the charts in fanfare and attention, but what was the real impact on risk First, it is worth noting that this bug is more properly classified as a new attack technique...
 
 
 
 
 
Expand article

Economist.com - Confessions of a Risk Manager

2008-08-11 08:42:00 by Security Retentive in Security Retentive
 
I was reading the Economist this week and came across an excellent article titled " Confessions of a Risk Manager In the article a risk manager for a major financial institution talks about managing risks and how the risk department was viewed as an obstacle by the rest of the business. I'll just quote a section here so you can see that...
 
 
 
 
 
Expand article

Evolution of IT Security to Risk; driving IT GRC acceptance?

2008-04-24 21:32:00 by Ryan Shopp in practical risk management
 
Great summary by Michael Rasmussen of Corporate Integrity on the 2008 State of the GRC market was posted earlier this month I believe the title of one of the sections itself summarizes one of the biggest benefits of GRC, "GRC is About Organization Collaboration." He is 100% correct from my perspective - independent of the people, technology and...
 
 
 
 
 
Expand article

Risk of Knowing Too Much About Risk

2008-03-06 06:24:50 by schneier in Schneier on Security
 
Interesting : Dread is a powerful force. The problem with dread is that it leads to terrible decision-making Slovic says all of this results from how our brains process risk, which is in two ways. The first is intuitive, emotional and experience based. Not only do we fear more what we can't control, but we also fear more what we can imagine or...
 
 
 
 
 
Expand article

Risk and the Brain

2008-03-18 06:51:31 by schneier in Schneier on Security
 
New research on how the brain estimates risk: Using functional imaging in a simple gambling task in which risk was constantly changed, the researchers discovered that an early activation of the anterior insula of the brain was associated with mistakes in predicting risk The time course of the activation also indicated a role in rapid updating,...
 
 
 
 
 
Expand article

Risk and Culture

2008-05-21 05:19:59 by schneier in Schneier on Security
 
The Second National Risk and Culture Study , conducted by the Cultural Cognition Project at Yale Law School. Abstract Cultural Cognition refers to the disposition to conform one's beliefs about societal risks to one's preferences for how society should be organized. Based on surveys and experiments involving some 5,000 Americans, the Second...
 
 
 
 
 
Expand article

Is Your Firewall a High Risk Entity

2008-08-15 15:15:57 by Alex in RiskAnalys.is
 
Not trying to be overly snarky here, but I was reviewing some GRC product literature recently. And there was a screenshot of an application window showing how the software helps identify high risk entities. And in the screenshot, there were 5 of these entities listed, each with corresponding risk ratings (High/Medium/Low) and scores (really just...
 
 
 
 
 
Expand article

Fundamentalism in Risk & Security