<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wikid cool thinking on Infosec incentives</title>
	<atom:link href="http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Nick</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2956</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Fri, 15 Dec 2006 14:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2956</guid>
		<description>WiKID is short for Wireless Key IDentification.  Our CTO came up with both the phrase and the acronynm.  So in this instance it is a whiny technology department doing the brand image protection, not the marketing department, which we don&#039;t even have.  :).
I&#039;m glad to see some discussion about my post.   To be honest, I had been thinking about it for awhile but did not have the time to really do anything in detail, thus the &quot;artful dodges&quot; ;).
[Update: Adam corrected spelling before Nick even had a chance to whiney about his mistakes.]
</description>
		<content:encoded><![CDATA[<p>WiKID is short for Wireless Key IDentification.  Our CTO came up with both the phrase and the acronynm.  So in this instance it is a whiny technology department doing the brand image protection, not the marketing department, which we don&#8217;t even have.  :).<br />
I&#8217;m glad to see some discussion about my post.   To be honest, I had been thinking about it for awhile but did not have the time to really do anything in detail, thus the &#8220;artful dodges&#8221; ;).<br />
[Update: Adam corrected spelling before Nick even had a chance to whiney about his mistakes.]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2955</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 14 Dec 2006 14:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2955</guid>
		<description>Perhaps a better way to put it would be:
&quot;Understanding the probability distribution is the tough part&quot;.
I don&#039;t think the typical firm has decent information on this, in part because the N is small -- most firms don&#039;t get hit with &quot;important&quot; breaches enough to analyze things statistically, and sharing of details across firms is minimal.  However, part of the problem also is that things that could be measured, and which could contribute to an understanding of expected loss (in my probability distribution sense) are not captured.  For example, how many firms know how much PII they have, where it is, and how much of it is moving around?  How many know measure these things over time?
</description>
		<content:encoded><![CDATA[<p>Perhaps a better way to put it would be:<br />
&#8220;Understanding the probability distribution is the tough part&#8221;.<br />
I don&#8217;t think the typical firm has decent information on this, in part because the N is small &#8212; most firms don&#8217;t get hit with &#8220;important&#8221; breaches enough to analyze things statistically, and sharing of details across firms is minimal.  However, part of the problem also is that things that could be measured, and which could contribute to an understanding of expected loss (in my probability distribution sense) are not captured.  For example, how many firms know how much PII they have, where it is, and how much of it is moving around?  How many know measure these things over time?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Jaquith</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2954</link>
		<dc:creator>Andrew Jaquith</dc:creator>
		<pubDate>Thu, 14 Dec 2006 01:26:21 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2954</guid>
		<description>The fallacy of this whole argument is that &quot;average&quot; losses cannot be applied to any particular incident. Losses are dominated by outliers. ALE is information security&#039;s spherical cow.
That said, Nick&#039;s observation is wonderfully perceptive. I haven&#039;t read his post in full, so the artful inclusion of &quot;if you agree with...&quot; is an elegant fudge.
</description>
		<content:encoded><![CDATA[<p>The fallacy of this whole argument is that &#8220;average&#8221; losses cannot be applied to any particular incident. Losses are dominated by outliers. ALE is information security&#8217;s spherical cow.<br />
That said, Nick&#8217;s observation is wonderfully perceptive. I haven&#8217;t read his post in full, so the artful inclusion of &#8220;if you agree with&#8230;&#8221; is an elegant fudge.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2953</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 13 Dec 2006 19:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2953</guid>
		<description>What the heck is the extra K capitalized for?  I thought the trick was that the ID was capitalized.
PS: Whiner! :)
</description>
		<content:encoded><![CDATA[<p>What the heck is the extra K capitalized for?  I thought the trick was that the ID was capitalized.<br />
PS: Whiner! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2952</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Wed, 13 Dec 2006 13:58:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2952</guid>
		<description>Oh, and Adam, it&#039;s WiKID, not WikID or Wikid; pronounced like wicked, of course. I&#039;m sure you wouldn&#039;t write iBM.  The inflection creates a whole different connotation ;).
</description>
		<content:encoded><![CDATA[<p>Oh, and Adam, it&#8217;s WiKID, not WikID or Wikid; pronounced like wicked, of course. I&#8217;m sure you wouldn&#8217;t write iBM.  The inflection creates a whole different connotation ;).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2951</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Wed, 13 Dec 2006 13:50:33 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2951</guid>
		<description>Chris:
Well, a big assumption is that you are protecting personal, non-public information.  You increasing have data points about that as references in the Ponemon Institute study that you can use.
You could also argue that doing the things that protect that data would also protect you from corporate esponiage, etc.
nick
</description>
		<content:encoded><![CDATA[<p>Chris:<br />
Well, a big assumption is that you are protecting personal, non-public information.  You increasing have data points about that as references in the Ponemon Institute study that you can use.<br />
You could also argue that doing the things that protect that data would also protect you from corporate esponiage, etc.<br />
nick</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2006/12/wikid-cool-thinking-on-infosec-incentives.html/comment-page-1#comment-2950</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 13 Dec 2006 12:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2106#comment-2950</guid>
		<description>Coming up with that ALE is the tough part.
</description>
		<content:encoded><![CDATA[<p>Coming up with that ALE is the tough part.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

