<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My Advice for the Pragmatic CSO</title>
	<atom:link href="http://emergentchaos.com/archives/2006/12/my-advice-for-the-pragmatic-cso.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2006/12/my-advice-for-the-pragmatic-cso.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2006/12/my-advice-for-the-pragmatic-cso.html/comment-page-1#comment-2977</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 20 Dec 2006 18:02:48 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2121#comment-2977</guid>
		<description>Out of context?  Please tell, what&#039;s the additional context needed?  I believe Gordon and Loeb to be an important partnership-they&#039;ve published important papers (I&#039;ve bemoaned them not being available online in the past), and an important book.
In both a paper and their book, they explain, in depth, the reason they say to cap spending at 37% based on a continuous,  price curve.  It&#039;s easy to argue that prices are not contiguous, and there are (as Nick Owen has pointed out) other critiques.  But you were incitefuly dismissive.
</description>
		<content:encoded><![CDATA[<p>Out of context?  Please tell, what&#8217;s the additional context needed?  I believe Gordon and Loeb to be an important partnership-they&#8217;ve published important papers (I&#8217;ve bemoaned them not being available online in the past), and an important book.<br />
In both a paper and their book, they explain, in depth, the reason they say to cap spending at 37% based on a continuous,  price curve.  It&#8217;s easy to argue that prices are not contiguous, and there are (as Nick Owen has pointed out) other critiques.  But you were incitefuly dismissive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick Owen, the Whiny</title>
		<link>http://emergentchaos.com/archives/2006/12/my-advice-for-the-pragmatic-cso.html/comment-page-1#comment-2976</link>
		<dc:creator>Nick Owen, the Whiny</dc:creator>
		<pubDate>Wed, 20 Dec 2006 16:53:12 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2121#comment-2976</guid>
		<description>Mike:
Did you read my (http://www.wikidsystems.com/WiKIDBlog/incentive-plan-for-an-information-security-team) original post?  I think I was pretty clear that you could pick your own percentage. Consider:
&quot;First, assume that you believe, as discussed in Gordon &amp; Loeb&#039;s book Managing Cybersecurity Resources: A Cost-Benefit Analysis and  discussed here that an organization should spend no more than 37%&quot;
and, pertinently:
&quot;If this cap doesn&#039;t work for you, then you can do more research or negotiate a cap.&quot;
or, to sum:
&quot;So there it is, just a simple, starting point proposal.&quot;
I posted a response to responses:  &lt;a href=&quot;http://www.wikidsystems.com/WiKIDBlog/response-to-responses-incentive-plans-for-information-security-professionals,&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://www.wikidsystems.com/WiKIDBlog/response-to-responses-incentive-plans-for-information-security-professionals,&quot; rel=&quot;nofollow&quot;&gt;http://www.wikidsystems.com/WiKIDBlog/response-to-responses-incentive-plans-for-information-security-professionals,&lt;/a&gt;&lt;/a&gt; since I took umbrage at some of the responses posted by the grump-meisters at Emergent Chaos.
</description>
		<content:encoded><![CDATA[<p>Mike:<br />
Did you read my (<a href="http://www.wikidsystems.com/WiKIDBlog/incentive-plan-for-an-information-security-team" rel="nofollow">http://www.wikidsystems.com/WiKIDBlog/incentive-plan-for-an-information-security-team</a>) original post?  I think I was pretty clear that you could pick your own percentage. Consider:<br />
&#8220;First, assume that you believe, as discussed in Gordon &#038; Loeb&#8217;s book Managing Cybersecurity Resources: A Cost-Benefit Analysis and  discussed here that an organization should spend no more than 37%&#8221;<br />
and, pertinently:<br />
&#8220;If this cap doesn&#8217;t work for you, then you can do more research or negotiate a cap.&#8221;<br />
or, to sum:<br />
&#8220;So there it is, just a simple, starting point proposal.&#8221;<br />
I posted a response to responses:  <a href="http://www.wikidsystems.com/WiKIDBlog/response-to-responses-incentive-plans-for-information-security-professionals," rel="nofollow"></a><a href="http://www.wikidsystems.com/WiKIDBlog/response-to-responses-incentive-plans-for-information-security-professionals," rel="nofollow">http://www.wikidsystems.com/WiKIDBlog/response-to-responses-incentive-plans-for-information-security-professionals,</a> since I took umbrage at some of the responses posted by the grump-meisters at Emergent Chaos.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Rothman</title>
		<link>http://emergentchaos.com/archives/2006/12/my-advice-for-the-pragmatic-cso.html/comment-page-1#comment-2975</link>
		<dc:creator>Mike Rothman</dc:creator>
		<pubDate>Wed, 20 Dec 2006 16:04:55 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2121#comment-2975</guid>
		<description>Grumpy grumpy grumpy. Nice job of taking my snippet out of context Adam. The reality is that little snippets of this book (like don&#039;t spend more than 37% on security) traverse the Internet and pick up steam. I wanted to share my opinion that putting an arbitrary cap on what you should do from a security budgeting standpoint didn&#039;t make sense to me.
And if I recall correctly, you&#039;ve gotten some &quot;incite&quot; from my work in the past. :-)
</description>
		<content:encoded><![CDATA[<p>Grumpy grumpy grumpy. Nice job of taking my snippet out of context Adam. The reality is that little snippets of this book (like don&#8217;t spend more than 37% on security) traverse the Internet and pick up steam. I wanted to share my opinion that putting an arbitrary cap on what you should do from a security budgeting standpoint didn&#8217;t make sense to me.<br />
And if I recall correctly, you&#8217;ve gotten some &#8220;incite&#8221; from my work in the past. :-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

