Quantitative Risk Assessments - possible or crack dream?

Presented at ShmooCon I (2005), Feb. 5, 2005, 3 p.m. (60 minutes)

With the increasing need to think carefully about where security dollars should be spent, companies are getting really enthusiastic about the idea of using risk assessments to decide what the "biggest" problems are and what the "best" way to solve them is. Being the engineering dweebs that most of us are, the obvious answer is to find numbers that represent everything and then figure out the answer. E.g. quantitatively.

Unfortunately that seems to fall into the category of a Hard Problem(tm). The only people who come close to doing this are insurance companies and they can't do it for IT-related risk yet. So everyone does "qualitative" risk assessments. E.g. they look at the problem, try to think about it in a structured fashion and then decide the risk, mostly on gut feel. NIST did a study a while back and found that quantitative risk assessments are much much more expensive than qualitative ones and not much more accurate.

So my question to y'all is: Is it ever likely to be possible to perform quantitative risk assessments for security-related risks and if so, what needs to happen (new tech, more data, better ouija boards) to make it possible.


Presenters:

  • Toby Kohlenberg - Senior Information Security Analyst, Intel Corporation
    Toby Kohlenberg is a senior information security specialist for Intel Corporation. He has extensive experience in penetration testing, incident response, architecture design and review, IDS, new technology analysis and various other things that paranoid geeks are likely to spend time dealing with. In the last couple years he has been responsible for developing security architectures for world-wide deployments of secure WLANs, Windows 2000/Active Directory, and IDS technologies and solutions. He is a handler for the Internet Storm Center and a co-author of the book Snort 2.1 from Syngress. He currently holds the CISSP, GCFW, GCIH and GCIA certifications.

Links:

Similar Presentations: