Skip to main content

The WiKID Blog

Viewing posts tagged Security and Economics

risk-and-effectiveness-for-project-evaluation

Gunnar Peterson has a post from Metricon about Bryan Ware's presentation about combining the effectiveness of a solution and the risk involved. I couldn't find the link to the actualy presentation. (I didn't have the time to go through them all.)

I think I would tie the effectiveness of the proposed security solution to the cost of capital of the overall project. It would be interesting to tie Bryan's work with my "work" on estimating the cost of capital for an information security project.

incentive-plan-for-an-information-security-team

It has occurred to me that you could develop an interesting incentive program for an information security team, assuming that you believe a couple of data points (or can come up with your own) and your primary concern is a data breach. In my opinion, security people are all too often incented only to maintain security - not to optimize the investment in security. Interests need to be aligned.

response-to-responses-incentive-plans-for


My recent (assumption laden and simplistic) post on incentive plans for an information security team was picked up by Adam and subsequently poked at by mordaxus and then piled on by Mike Rothman.

punishment-and-security

There is a very article in the NY Times about how groups can profit by punishing members, in particular, by punishing free riders.

In the experiment, investigators at the University of Erfurt in Germany enrolled 84 students in the investment game and gave them 20 tokens apiece to start. In each round of the game, every participant decided whether to hold on to the tokens or invest some of them in a fund whose guaranteed profit was distributed equally among all members of the group, including the "free riders" who sat on their money. Because the profit was determined by a multiple of the tokens invested, each participant who contributed to the fund enjoyed less of a return than if the free riders had done so as well.

hedge-fund-management-and-information-security

Been a long time since I posted anything. I'm trying to get back into the swing.

Recent Posts

Archive

2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008

Categories

Tags

Authors

Feeds

RSS / Atom