Job: Security - posts tagged 'threat modeling' http://soup.rachner.us/ Job: Security - posts tagged 'threat modeling' - posts tagged 'threat modeling' http://soup.rachner.us/ http://7.asset.soup.io/asset/0506/3271_6289.jpeg 264 273 Eric Rachner's observations on information security, hacking, and the business of IT risk and compliance. A Grain of Salt for Digital Asset Values {"tags":["threat modeling","doingitwrong"],"type":"regular","title":"A Grain of Salt for Digital Asset Values","source":null,"body":"\u003C!--[if gte mso 9]\u003E\u003Cxml\u003E\n \u003Cw:worddocument\u003E\n \u003Cw:view\u003ENormal\u003C/w:view\u003E\n \u003Cw:zoom\u003E0\u003C/w:zoom\u003E\n \u003Cw:trackmoves/\u003E\n \u003Cw:trackformatting/\u003E\n \u003Cw:punctuationkerning/\u003E\n \u003Cw:validateagainstschemas/\u003E\n \u003Cw:saveifxmlinvalid\u003Efalse\u003C/w:saveifxmlinvalid\u003E\n \u003Cw:ignoremixedcontent\u003Efalse\u003C/w:ignoremixedcontent\u003E\n \u003Cw:alwaysshowplaceholdertext\u003Efalse\u003C/w:alwaysshowplaceholdertext\u003E\n \u003Cw:donotpromoteqf/\u003E\n \u003Cw:lidthemeother\u003EEN-US\u003C/w:lidthemeother\u003E\n \u003Cw:lidthemeasian\u003EX-NONE\u003C/w:lidthemeasian\u003E\n \u003Cw:lidthemecomplexscript\u003EX-NONE\u003C/w:lidthemecomplexscript\u003E\n \u003Cw:compatibility\u003E\n \u003Cw:breakwrappedtables/\u003E\n \u003Cw:snaptogridincell/\u003E\n \u003Cw:wraptextwithpunct/\u003E\n \u003Cw:useasianbreakrules/\u003E\n \u003Cw:dontgrowautofit/\u003E\n \u003Cw:splitpgbreakandparamark/\u003E\n \u003Cw:dontvertaligncellwithsp/\u003E\n \u003Cw:dontbreakconstrainedforcedtables/\u003E\n \u003Cw:dontvertalignintxbx/\u003E\n \u003Cw:word11kerningpairs/\u003E\n \u003Cw:cachedcolbalance/\u003E\n \u003C/w:compatibility\u003E\n \u003Cm:mathpr\u003E\n \u003Cm:mathfont m:val=\"Cambria Math\"/\u003E\n \u003Cm:brkbin m:val=\"before\"/\u003E\n \u003Cm:brkbinsub m:val=\"\u0026#45;-\"/\u003E\n \u003Cm:smallfrac m:val=\"off\"/\u003E\n \u003Cm:dispdef/\u003E\n \u003Cm:lmargin m:val=\"0\"/\u003E\n \u003Cm:rmargin m:val=\"0\"/\u003E\n \u003Cm:defjc m:val=\"centerGroup\"/\u003E\n \u003Cm:wrapindent m:val=\"1440\"/\u003E\n \u003Cm:intlim m:val=\"subSup\"/\u003E\n \u003Cm:narylim m:val=\"undOvr\"/\u003E\n \u003C/m:mathpr\u003E\u003C/w:worddocument\u003E\n\u003C/xml\u003E\u003C![endif]--\u003E\u003C!--[if gte mso 9]\u003E\u003Cxml\u003E\n \u003Cw:latentstyles deflockedstate=\"false\" defunhidewhenused=\"true\"\n defsemihidden=\"true\" defqformat=\"false\" defpriority=\"99\"\n latentstylecount=\"267\"\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"0\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Normal\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"heading 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 7\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 8\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"9\" qformat=\"true\" name=\"heading 9\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 7\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 8\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" name=\"toc 9\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"35\" qformat=\"true\" name=\"caption\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"10\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Title\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"1\" name=\"Default Paragraph Font\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"11\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Subtitle\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"22\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Strong\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"20\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Emphasis\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"59\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Table Grid\"/\u003E\n \u003Cw:lsdexception locked=\"false\" unhidewhenused=\"false\" name=\"Placeholder Text\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"1\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"No Spacing\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" unhidewhenused=\"false\" name=\"Revision\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"34\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"List Paragraph\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"29\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Quote\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"30\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Intense Quote\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3 Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid Accent 1\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3 Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid Accent 2\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3 Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid Accent 3\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3 Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid Accent 4\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3 Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid Accent 5\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"60\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Shading Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"61\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light List Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"62\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Light Grid Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"63\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 1 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"64\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Shading 2 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"65\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 1 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"66\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium List 2 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"67\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 1 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"68\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 2 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"69\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Medium Grid 3 Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"70\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Dark List Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"71\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Shading Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"72\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful List Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"73\" semihidden=\"false\"\n unhidewhenused=\"false\" name=\"Colorful Grid Accent 6\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"19\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Subtle Emphasis\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"21\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Intense Emphasis\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"31\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Subtle Reference\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"32\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Intense Reference\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"33\" semihidden=\"false\"\n unhidewhenused=\"false\" qformat=\"true\" name=\"Book Title\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"37\" name=\"Bibliography\"/\u003E\n \u003Cw:lsdexception locked=\"false\" priority=\"39\" qformat=\"true\" name=\"TOC Heading\"/\u003E\n \u003C/w:latentstyles\u003E\n\u003C/xml\u003E\u003C![endif]--\u003E\n\u0026amp;amp;amp;amp;amp;amp;amp;lt;!--\n /* Font Definitions */\n @font-face\n\t{font-family:Wingdings;\n\tpanose-1:5 0 0 0 0 0 0 0 0 0;\n\tmso-font-charset:2;\n\tmso-generic-font-family:auto;\n\tmso-font-pitch:variable;\n\tmso-font-signature:0 268435456 0 0 -2147483648 0;}\n@font-face\n\t{font-family:\"Cambria Math\";\n\tpanose-1:2 4 5 3 5 4 6 3 2 4;\n\tmso-font-charset:1;\n\tmso-generic-font-family:roman;\n\tmso-font-format:other;\n\tmso-font-pitch:variable;\n\tmso-font-signature:0 0 0 0 0 0;}\n@font-face\n\t{font-family:Calibri;\n\tpanose-1:2 15 5 2 2 2 4 3 2 4;\n\tmso-font-charset:0;\n\tmso-generic-font-family:swiss;\n\tmso-font-pitch:variable;\n\tmso-font-signature:-1610611985 1073750139 0 0 159 0;}\n /* Style Definitions */\n p.MsoNormal, li.MsoNormal, div.MsoNormal\n\t{mso-style-unhide:no;\n\tmso-style-qformat:yes;\n\tmso-style-parent:\"\";\n\tmargin-top:0in;\n\tmargin-right:0in;\n\tmargin-bottom:10.0pt;\n\tmargin-left:0in;\n\tline-height:115%;\n\tmso-pagination:widow-orphan;\n\tfont-size:11.0pt;\n\tfont-family:\"Calibri\",\"sans-serif\";\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-fareast-font-family:Calibri;\n\tmso-fareast-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;\n\tmso-bidi-font-family:\"Times New Roman\";\n\tmso-bidi-theme-font:minor-bidi;}\na:link, span.MsoHyperlink\n\t{mso-style-priority:99;\n\tcolor:blue;\n\ttext-decoration:underline;\n\ttext-underline:single;}\na:visited, span.MsoHyperlinkFollowed\n\t{mso-style-noshow:yes;\n\tmso-style-priority:99;\n\tcolor:purple;\n\tmso-themecolor:followedhyperlink;\n\ttext-decoration:underline;\n\ttext-underline:single;}\np.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph\n\t{mso-style-priority:34;\n\tmso-style-unhide:no;\n\tmso-style-qformat:yes;\n\tmargin-top:0in;\n\tmargin-right:0in;\n\tmargin-bottom:10.0pt;\n\tmargin-left:.5in;\n\tmso-add-space:auto;\n\tline-height:115%;\n\tmso-pagination:widow-orphan;\n\tfont-size:11.0pt;\n\tfont-family:\"Calibri\",\"sans-serif\";\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-fareast-font-family:Calibri;\n\tmso-fareast-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;\n\tmso-bidi-font-family:\"Times New Roman\";\n\tmso-bidi-theme-font:minor-bidi;}\np.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst\n\t{mso-style-priority:34;\n\tmso-style-unhide:no;\n\tmso-style-qformat:yes;\n\tmso-style-type:export-only;\n\tmargin-top:0in;\n\tmargin-right:0in;\n\tmargin-bottom:0in;\n\tmargin-left:.5in;\n\tmargin-bottom:.0001pt;\n\tmso-add-space:auto;\n\tline-height:115%;\n\tmso-pagination:widow-orphan;\n\tfont-size:11.0pt;\n\tfont-family:\"Calibri\",\"sans-serif\";\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-fareast-font-family:Calibri;\n\tmso-fareast-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;\n\tmso-bidi-font-family:\"Times New Roman\";\n\tmso-bidi-theme-font:minor-bidi;}\np.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle\n\t{mso-style-priority:34;\n\tmso-style-unhide:no;\n\tmso-style-qformat:yes;\n\tmso-style-type:export-only;\n\tmargin-top:0in;\n\tmargin-right:0in;\n\tmargin-bottom:0in;\n\tmargin-left:.5in;\n\tmargin-bottom:.0001pt;\n\tmso-add-space:auto;\n\tline-height:115%;\n\tmso-pagination:widow-orphan;\n\tfont-size:11.0pt;\n\tfont-family:\"Calibri\",\"sans-serif\";\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-fareast-font-family:Calibri;\n\tmso-fareast-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;\n\tmso-bidi-font-family:\"Times New Roman\";\n\tmso-bidi-theme-font:minor-bidi;}\np.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast\n\t{mso-style-priority:34;\n\tmso-style-unhide:no;\n\tmso-style-qformat:yes;\n\tmso-style-type:export-only;\n\tmargin-top:0in;\n\tmargin-right:0in;\n\tmargin-bottom:10.0pt;\n\tmargin-left:.5in;\n\tmso-add-space:auto;\n\tline-height:115%;\n\tmso-pagination:widow-orphan;\n\tfont-size:11.0pt;\n\tfont-family:\"Calibri\",\"sans-serif\";\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-fareast-font-family:Calibri;\n\tmso-fareast-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;\n\tmso-bidi-font-family:\"Times New Roman\";\n\tmso-bidi-theme-font:minor-bidi;}\n.MsoChpDefault\n\t{mso-style-type:export-only;\n\tmso-default-props:yes;\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-fareast-font-family:Calibri;\n\tmso-fareast-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;\n\tmso-bidi-font-family:\"Times New Roman\";\n\tmso-bidi-theme-font:minor-bidi;}\n.MsoPapDefault\n\t{mso-style-type:export-only;\n\tmargin-bottom:10.0pt;\n\tline-height:115%;}\n@\u0026amp;amp;amp;amp;amp;amp;lt;a href=\"http://page.soup.io\"\u0026amp;amp;amp;amp;amp;amp;gt;page\u0026amp;amp;amp;amp;amp;amp;lt;/a\u0026amp;amp;amp;amp;amp;amp;gt; Section1\n\t{size:8.5in 11.0in;\n\tmargin:1.0in 1.0in 1.0in 1.0in;\n\tmso-header-margin:.5in;\n\tmso-footer-margin:.5in;\n\tmso-paper-source:0;}\ndiv.Section1\n\t{page:Section1;}\n /* List Definitions */\n @list l0\n\t{mso-list-id:1023358003;\n\tmso-list-type:hybrid;\n\tmso-list-template-ids:-1676016582 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}\n@list l0:level1\n\t{mso-level-number-format:bullet;\n\tmso-level-text:\uf0b7;\n\tmso-level-tab-stop:none;\n\tmso-level-number-position:left;\n\ttext-indent:-.25in;\n\tfont-family:Symbol;}\nol\n\t{margin-bottom:0in;}\nul\n\t{margin-bottom:0in;}\n--\u0026amp;amp;amp;amp;amp;amp;amp;gt;\n\u003C!--[if gte mso 10]\u003E\n\u003Cstyle\u003E\n /* Style Definitions */\n table.MsoNormalTable\n\t{mso-style-name:\"Table Normal\";\n\tmso-tstyle-rowband-size:0;\n\tmso-tstyle-colband-size:0;\n\tmso-style-noshow:yes;\n\tmso-style-priority:99;\n\tmso-style-qformat:yes;\n\tmso-style-parent:\"\";\n\tmso-padding-alt:0in 5.4pt 0in 5.4pt;\n\tmso-para-margin-top:0in;\n\tmso-para-margin-right:0in;\n\tmso-para-margin-bottom:10.0pt;\n\tmso-para-margin-left:0in;\n\tline-height:115%;\n\tmso-pagination:widow-orphan;\n\tfont-size:11.0pt;\n\tfont-family:\"Calibri\",\"sans-serif\";\n\tmso-ascii-font-family:Calibri;\n\tmso-ascii-theme-font:minor-latin;\n\tmso-hansi-font-family:Calibri;\n\tmso-hansi-theme-font:minor-latin;}\n\u003C/style\u003E\n\u003C![endif]--\u003E\n\n\u003Cp\u003EA \u003Ca href=\"http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/\"\u003Erecent\u003C/a\u003E\n\u003Ca href=\"http://blogs.forrester.com/srm/2009/10/information-asset-value-some-coldhearted-calculations-.html\"\u003Eflurry\u003C/a\u003E\nof \u003Ca href=\"http://communities.intel.com/community/openportit/it/blog/2009/10/22/how-to-value-digital-assets\"\u003Eblog\u003C/a\u003E\n\u003Ca href=\"http://newschoolsecurity.com/2009/10/on-the-value-of-digital-asset-value-for-security-decisions/\"\u003Eposts\u003C/a\u003E\nby some very smart people has reminded me of how in my former life at Microsoft,\nI often found myself in meetings whose agenda included tallying up the\nso-called \"digital assets\" related to a given project.\u003Cbr /\u003E\n\u003Cbr /\u003E\nFor the uninitiated, the \"digital asset\" is the starting point in\npretty much every formal and semi-formal IT risk analysis exercise, to\nwit:\u00a0 What are we protecting, after all, if not assets? What uniquely\ndigital threats imperil these assets, and how awful would it be if any of those\nthreats should be realized, and what are the potential mitigations for each\nthreat, and what is the cost of each contemplated mitigation, and can I somehow\navoid being summoned to any more of these meetings, or do I need to step up my\nsearch for a new position in the company?\u003C/p\u003E\n\n\u003Cp\u003EGranted, as a starting point for getting a handle on your\nsecurity spend, it seems only reasonable to boil everything down to a finite\nlist of items. \u00a0The obvious next step is,\nlet\u2019s appraise the items in our list according to some kind of valuation scheme,\nand start sorting.\u00a0 There\u2019s \u003Ca href=\"http://www.cert.org/octave/\"\u003Eplenty\u003C/a\u003E of \u003Ca href=\"http://www.octotrike.org/\"\u003Emethodologies\u003C/a\u003E to \u003Ca href=\"http://msdn.microsoft.com/en-us/security/aa570413.aspx\"\u003Epick\u003C/a\u003E \u003Ca href=\"http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/\"\u003Efrom\u003C/a\u003E.\u003C/p\u003E\n\n\u003Cp\u003EExcept that we\u2019re not \u003Ca href=\"http://www.theonion.com/content/news/tina_turner_burns_down_legs_for\"\u003Einsuring\nTina Turner\u2019s legs\u003C/a\u003E here.\u00a0 I contend that there is \u003Ci\u003Eno useful relationship \u003C/i\u003Ebetween\nasset value and loss-per-incident.\u003C/p\u003E\n\n\u003Cp\u003EWith that claim in mind, let\u2019s review the types of costs\nassociated with typical real-world hacking incidents, and ask ourselves which\nof these costs will vary according to some pre-estimated value of the compromised\ndigital assets:\u003C/p\u003E\u003Cp\u003E* Engagement of incident response specialists\u003Cbr /\u003E* Damage to reputation / loss of future business\u003Cbr /\u003E* Loss of business advantage (e.g., leakage of details concerning payroll, pending deals, R\u0026amp;D, etc.)\u003Cbr /\u003E* Direct financial loss (e.g., fraudulent transactions)\u003Cbr /\u003E* Disruption of regular business operations\u003Cbr /\u003E* Fines and penalties\u003C/p\u003E\u003Cp\u003E\u003C!--[if !supportLists]--\u003EActually, I wrote that list in order, ranging from \u201cno\nrelationship to asset values\u201d to \u201cperhaps some vague, tenuous relationship.\u201d\u003C/p\u003E\n\n\u003Cp\u003ESure, the cost of an hour\u2019s operational disruption might be\nestimable in advance, especially when service level agreements are in place.\u00a0 But when we attempt to quantify the cost of\ndowntime, are we even talking about \u003Ci\u003Eassets\u003C/i\u003E\nany more?\u003C/p\u003E\n\nAnd is it possible that when we fetishize over\nthe valuations of individual data assets, we\u2019re taking our eyes off the\nloss-avoidance ball?"} &lt;!--[if gte mso 9]>&lt;xml> &lt;w:worddocument> &lt;w:view>Normal&lt;/w:view> &lt;w:zoom>0&lt;/w:zoom> &lt;w:trackmoves/> &lt;w:trackformatting/> &lt;w:punctuationkerning/> &lt;w:validateagainstschemas/> &lt;w:saveifxmlinvalid>false&lt;/w:saveifxmlinvalid> &lt;w:ignoremixedcontent>false&lt;/w:ignoremixedcontent> &lt;w:alwaysshowplaceholdertext>false&lt;/w:alwaysshowplaceholdertext> &lt;w:donotpromoteqf/> &lt;w:lidthemeother>EN-US&lt;/w:lidthemeother> &lt;w:lidthemeasian>X-NONE&lt;/w:lidthemeasian> &lt;w:lidthemecomplexscript>X-NONE&lt;/w:lidthemecomplexscript> &lt;w:compatibility> &lt;w:breakwrappedtables/> &lt;w:snaptogridincell/> &lt;w:wraptextwithpunct/> &lt;w:useasianbreakrules/> &lt;w:dontgrowautofit/> &lt;w:splitpgbreakandparamark/> &lt;w:dontvertaligncellwithsp/> &lt;w:dontbreakconstrainedforcedtables/> &lt;w:dontvertalignintxbx/> &lt;w:word11kerningpairs/> &lt;w:cachedcolbalance/> &lt;/w:compatibility> &lt;m:mathpr> &lt;m:mathfont m:val="Cambria Math"/> &lt;m:brkbin m:val="before"/> &lt;m:brkbinsub m:val="&#45;-"/> &lt;m:smallfrac m:val="off"/> &lt;m:dispdef/> &lt;m:lmargin m:val="0"/> &lt;m:rmargin m:val="0"/> &lt;m:defjc m:val="centerGroup"/> &lt;m:wrapindent m:val="1440"/> &lt;m:intlim m:val="subSup"/> &lt;m:narylim m:val="undOvr"/> &lt;/m:mathpr>&lt;/w:worddocument> &lt;/xml>&lt;![endif]-->&lt;!--[if gte mso 9]>&lt;xml> &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"> &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"/> &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"/> &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"/> &lt;w:lsdexception locked="false" priority="39" name="toc 1"/> &lt;w:lsdexception locked="false" priority="39" name="toc 2"/> &lt;w:lsdexception locked="false" priority="39" name="toc 3"/> &lt;w:lsdexception locked="false" priority="39" name="toc 4"/> &lt;w:lsdexception locked="false" priority="39" name="toc 5"/> &lt;w:lsdexception locked="false" priority="39" name="toc 6"/> &lt;w:lsdexception locked="false" priority="39" name="toc 7"/> &lt;w:lsdexception locked="false" priority="39" name="toc 8"/> &lt;w:lsdexception locked="false" priority="39" name="toc 9"/> &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"/> &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"/> &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"/> &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"/> &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"/> &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"/> &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"/> &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"/> &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"/> &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"/> &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"/> &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"/> &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"/> &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"/> &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"/> &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"/> &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"/> &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"/> &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"/> &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"/> &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"/> &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"/> &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"/> &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"/> &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"/> &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"/> &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"/> &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"/> &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"/> &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"/> &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"/> &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"/> &lt;w:lsdexception locked="false" priority="37" name="Bibliography"/> &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"/> &lt;/w:latentstyles> &lt;/xml>&lt;![endif]--> &amp;amp;amp;amp;amp;amp;amp;lt;!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0; mso-font-charset:2; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:0 268435456 0 0 -2147483648 0;} @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:1; mso-generic-font-family:roman; mso-font-format:other; mso-font-pitch:variable; mso-font-signature:0 0 0 0 0 0;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline; text-underline:single;} a:visited, span.MsoHyperlinkFollowed {mso-style-noshow:yes; mso-style-priority:99; color:purple; mso-themecolor:followedhyperlink; text-decoration:underline; text-underline:single;} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {mso-style-priority:34; mso-style-unhide:no; mso-style-qformat:yes; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:.5in; mso-add-space:auto; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst {mso-style-priority:34; mso-style-unhide:no; mso-style-qformat:yes; mso-style-type:export-only; margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; mso-add-space:auto; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle {mso-style-priority:34; mso-style-unhide:no; mso-style-qformat:yes; mso-style-type:export-only; margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; mso-add-space:auto; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast {mso-style-priority:34; mso-style-unhide:no; mso-style-qformat:yes; mso-style-type:export-only; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:.5in; mso-add-space:auto; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} .MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} .MsoPapDefault {mso-style-type:export-only; margin-bottom:10.0pt; line-height:115%;} @&amp;amp;amp;amp;amp;amp;lt;a href="<a href="http://page.soup.io&quot;&amp;amp;amp;amp;amp;amp;gt;page&amp;amp;amp;amp;amp;amp;lt;/a&amp;amp;amp;amp;amp;amp;gt">http://page.soup.io&quot;&amp;amp;amp;amp;amp;amp;amp;gt;page&amp;amp;amp;amp;amp;amp;amp;lt;/a&amp;amp;amp;amp;amp;amp;amp;gt</a>; Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;} div.Section1 {page:Section1;} /* List Definitions */ @list l0 {mso-list-id:1023358003; mso-list-type:hybrid; mso-list-template-ids:-1676016582 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 {mso-level-number-format:bullet; mso-level-text:; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} --&amp;amp;amp;amp;amp;amp;amp;gt; &lt;!--[if gte mso 10]> &lt;style> /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin-top:0in; mso-para-margin-right:0in; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin;} &lt;/style> &lt;![endif]--> <p>A <a href="http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/">recent</a> <a href="http://blogs.forrester.com/srm/2009/10/information-asset-value-some-coldhearted-calculations-.html">flurry</a> of <a href="http://communities.intel.com/community/openportit/it/blog/2009/10/22/how-to-value-digital-assets">blog</a> <a href="http://newschoolsecurity.com/2009/10/on-the-value-of-digital-asset-value-for-security-decisions/">posts</a> by some very smart people has reminded me of how in my former life at Microsoft, I often found myself in meetings whose agenda included tallying up the so-called "digital assets" related to a given project.<br /> <br /> For the uninitiated, the "digital asset" is the starting point in pretty much every formal and semi-formal IT risk analysis exercise, to wit:  What are we protecting, after all, if not assets? What uniquely digital threats imperil these assets, and how awful would it be if any of those threats should be realized, and what are the potential mitigations for each threat, and what is the cost of each contemplated mitigation, and can I somehow avoid being summoned to any more of these meetings, or do I need to step up my search for a new position in the company?</p> <p>Granted, as a starting point for getting a handle on your security spend, it seems only reasonable to boil everything down to a finite list of items.  The obvious next step is, let’s appraise the items in our list according to some kind of valuation scheme, and start sorting.  There’s <a href="http://www.cert.org/octave/">plenty</a> of <a href="http://www.octotrike.org/">methodologies</a> to <a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx">pick</a> <a href="http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/">from</a>.</p> <p>Except that we’re not <a href="http://www.theonion.com/content/news/tina_turner_burns_down_legs_for">insuring Tina Turner’s legs</a> here.  I contend that there is <i>no useful relationship </i>between asset value and loss-per-incident.</p> <p>With that claim in mind, let’s review the types of costs associated with typical real-world hacking incidents, and ask ourselves which of these costs will vary according to some pre-estimated value of the compromised digital assets:</p><p>* Engagement of incident response specialists<br />* Damage to reputation / loss of future business<br />* Loss of business advantage (e.g., leakage of details concerning payroll, pending deals, R&amp;D, etc.)<br />* Direct financial loss (e.g., fraudulent transactions)<br />* Disruption of regular business operations<br />* Fines and penalties</p><p>&lt;!--[if !supportLists]-->Actually, I wrote that list in order, ranging from “no relationship to asset values” to “perhaps some vague, tenuous relationship.”</p> <p>Sure, the cost of an hour’s operational disruption might be estimable in advance, especially when service level agreements are in place.  But when we attempt to quantify the cost of downtime, are we even talking about <i>assets</i> any more?</p> And is it possible that when we fetishize over the valuations of individual data assets, we’re taking our eyes off the loss-avoidance ball?Mon, 26 Oct 2009 06:53:09 GMThttp://soup.rachner.us/post/32537875/A-Grain-of-Salt-for-Digital-Asseturn:www-soup-io:1:32537875regularthreat modelingdoingitwrong