We cannot measure information risk. Not in monetary terms, not on any quantitative scale.
We can (and must) assess risk through lenses available, but to achieve business relevance we need an element of intersubjectivity. A metric shouldn't depend on what individuals happen to be involved.
Therefore, we need methods based on a common understanding of basic concepts. We could take a vote on what constitutes a "threat" but the fact that we need to take a vote is a reflection of low industry maturity.
(some of) my events
- 2021-09-21--23 Northern European Emergency and Disaster Studies (presenting at conference, Östersund)
- 2021-06-15--16 Stockholm Criminology Symposium (attending conference)
- 2021-03-29--06-04 Hållbar utveckling ur ett säkerhetsperspektiv (taking course, Karlstad University)
- 2021-01-18--06-04 Besluts- och riskanalys 3 (taking course, University of Gävle)
- 2021-01-14 Certifierad IT-arkitekt (guest lecturing, Stockholm)

Subscribe to:
Post Comments (Atom)
No comments:
Post a comment