A while ago I wrote about my concern that introducing the idea of risk into information security discussions too often leads to more analysis rather than productive action.
Over at BlogInfoSec.com Frank Cassano echoes similar thoughts: "The biggest mistake risk management professionals make today is that they over think their programs and forget the core truth of risk, stay alive." He describes how risk management pros can get caught up in "endless analysis" and not get on with the business of keeping the business alive.
It's the first post in "The Risk Rack" column, and I'm interested in seeing where he takes it.
Comments