A Notional Framework for applying Antifragile thinking to the RMF – Growing stronger through compromise

Presented at BSidesDC 2016, Oct. 23, 2016, 2:30 p.m. (50 minutes)

If you spend enough years in cyber security, you begin to notice cycles, influences, and trends, which substantially change the initial risk state of our systems, networks and organizations. When systems are designed and implemented, we assume a steady state risk model with little change. So the volatility of an unexpected event shatters our risk assumption, shocking individuals, teams, and organizations — any entity! This unexpected event is called a Black Swan; a “large-scale unpredictable and irregular event of massive consequence” that harms an entity. By attending this talk, you will learn the basics of: - The Risk Management Framework (RMF) Workflow - The difference between Fragile, Resilient, and Antifragile environments - How technology adoption makes our organizations more fragile and why we are always behind the curve - The influence on the standards and product cycles which create hidden fragility - How can you reduce the impact of a Cyber Black Swan event on your organization

Presenters:

  • Joe Klein - CTO at Disrupt6
    Joe Klein is a 35-year veteran of the IT and IA industry who is often requested to speak at professional security venues and routinely participates in high-level government and standards bodies working groups, as an expert in cyber security issues. He has extensive experience in DoD, US Government, and commercial sectors, focusing on information assurance, risk, network, IoT, IPv6 and other evolving security domains. Joe is CTO & Founder of Disrupt6, as well as former board member of ISSA-NOVA, a current member of NovaHackers, and NovaInfoSec.

Links:

Similar Presentations: