Archive

Archive for March 25th, 2010

Quote of Security – 11

March 25th, 2010 No comments

Why we need security metricsAnother way of thinking about it, specifically that if you want security then you must control the future, if you want to control the future then you must be able to draw conclusions from what you know, if you want to draw conclusions then the basis for those conclusions must be reproducible, and if you want reproducible bases you have to have a measurement regime.

- Dan Geer

Quote of Security – 10

March 25th, 2010 No comments

- Good enough is good enough.
- Good enough always beats perfect.
- The really hard part is determining what is good enough.

- by Ravi Sandhu

You can download the whole paper here.