<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Risk management in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10767#M988</link>
    <description>&lt;P&gt;good point, the stats I pulled were from various non-partisan gov't sources (and generally were close enough from disparate sources to suggest reasonable expectation of validity) . Were I, say referencing them for a College Paper, I doubt my 10 min of bouncing round the interwebs would count for much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The shooter race stats were LE analysis based on I believe observation of those committing the crime, again probably not exactly 1st level reference material, but it did seem to jive across multiple sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also agree that theres no easy solution, much like IT.&amp;nbsp; A firewall (or bullet proof glass) only protects against certain threats, there needs to be multiple mechanisms to address the full scope of risk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now where have I heard that before?&lt;/P&gt;</description>
    <pubDate>Fri, 25 May 2018 03:20:26 GMT</pubDate>
    <dc:creator>Dain</dc:creator>
    <dc:date>2018-05-25T03:20:26Z</dc:date>
    <item>
      <title>Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10541#M953</link>
      <description>&lt;P&gt;The Lt. Gov. of Texas says school shootings aren't happening because of guns. Instead, he blames:&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;- violent video games&lt;BR /&gt;&lt;BR /&gt;Oddly, here in Canada, we have violent video games.&amp;nbsp; Probably exactly the same ones that they have in the States.&amp;nbsp; All of my grandchildren have played them.&amp;nbsp; None of them have shot up their schools, yet.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;- removing religion from schools&lt;BR /&gt;&lt;BR /&gt;I suspect that, here in Canada, we started removing religion from schools earlier than in the States, and have gone farther in that regard.&amp;nbsp; We still have fewer school shooting funerals.&amp;nbsp; (Hockey bus crash funerals, yes.)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;- irresponsible gun owners&lt;BR /&gt;&lt;BR /&gt;No doubt some people will be surprised to find that people are allowed to own guns in Canada.&amp;nbsp; And some of our gun owners are extremely irresponsible.&amp;nbsp; (We just had a court case of someone who was astoundingly irresponsible in handling a gun.)&amp;nbsp; I suspect that this gets closer to the heart of the issue, but it still doesn't seem to account for the difference in numbers of school shootings between the US and Canada.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;- too many entrances to schools&lt;BR /&gt;&lt;BR /&gt;Here in Canada we have lots and lots of entrances to our schools.&amp;nbsp; Very few result in school shootings.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;- unarmed teachers&lt;BR /&gt;&lt;BR /&gt;It was probably a very good thing that I wasn't issued a gun when I was teaching elementary school.&amp;nbsp; Not that there weren't times that I would have dearly liked to use one.&amp;nbsp; (Actually, I would have been tempted much more during the times I taught in colleges and universities.&amp;nbsp; And for ISC2.&amp;nbsp; [Especially when I had Cisco employees in the seminars.]&amp;nbsp; But I digress.)&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 01:04:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10541#M953</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-05-22T01:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10564#M956</link>
      <description>&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although you titled this discussion&amp;nbsp;&lt;STRONG&gt;Risk Management&lt;/STRONG&gt; there are lots of relevant security issues in this discussion that we can address.&amp;nbsp; I'm a little concerned that you may have hijacked the forum for a debate on gun control though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a Risk Management discussion, I think that this is clearly manifestation of an&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;Insider Threat&lt;/STRONG&gt;&lt;/U&gt;: In nearly every school shooting that has made it on the news, the shooter was a current or recently terminated (graduated, suspended, etc.) student.&amp;nbsp; The shooting (school, workplace, etc.) itself is a symptom of the Insider Threat.&amp;nbsp; The symptom could have materialized several different ways including violence without guns (bombs, bladed weapons, etc.), property damage (arson, vandalism, destruction of IT infrastructure, etc.), and several other outcomes.&amp;nbsp; Unlike an external attacker where we are figuratively playing whack-a-mole with symptoms (probes, attacks, and asset recovery), we have the ability to interact with the insider and both identify and interdict the root cause before it manifests as an active threat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This case first illustrates&amp;nbsp;that there is a possibility that the popular Insider Threat detection model that typically rests with Information Systems &amp;amp; Technology Security ("IS&amp;amp;TS) staff is wrong.&amp;nbsp; I believe that the IS&amp;amp;TS have a part to play in detecting behavioral baseline changes within the IT systems, but the scope of "sensors" is limited to IS&amp;amp;T, and not to the bigger picture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The case secondly illustrates that the method that we deal with potential Insider Threats that we detect may be inappropriate.&amp;nbsp; It may be that the cultural norm is to avoid dealing with people in conflict, distress, experiencing poor mental health, and other social issues&amp;nbsp;because those relationships take much more effort than healthy ones.&amp;nbsp; Actions that exacerbate this would be (a) termination of the relationship (suspension or expulsion from school,&amp;nbsp;firing or suspending employment, etc.), or (b) simply ignoring the situation until we are forced to deal with it (because the Insider is pointing a gun at us, or deleted all our files).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To that end, I think that we currently lack proper focus (as opposed to magnitude of attention) on Insider Threat and that is derailing our ability to manage the risk properly.&amp;nbsp; I have seen very little in the way of actual studies on Root Cause Analysis for malicious insiders except for a handful of case studies by the U.S. Government.&amp;nbsp; Does anyone have public or scholarly resources on Root Cause Analysis for motivations of Insiders to resort to a malicious action?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 14:40:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10564#M956</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-22T14:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10609#M958</link>
      <description>&lt;P&gt;rslade,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I quickly progressed through several stages of thought when I read your posting. My first thought was confusion as I suspected it was intended for some gun control forum and accidentally posted to an information security site. I soon realized that it was not accidental and transitioned to my second thought; indignation from what I perceived as someone with no real-life experience in the U.S. attempting to chime in on a predominately American problem. This led to thoughts of irritation as I felt this person was trying to persuade readers that Canada is somehow superior to the U.S. because there are fewer mass shooting events north of the border. After re-reading your post and some deeper thought however, I realized that this is actually a&amp;nbsp;great metaphor for information security and the role that, as your title suggests, risk management plays.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; The Columbine High School massacre was the first major school shooting event in the U.S. and tragedies like that have sadly become more common over the last nearly 20 years. No doubt, the risk has increased but what specifically has changed over the last two decades to cause this? I recommend we dissect the issue based on something we know well - risks are comprised of vulnerabilities and threats.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Vulnerabilities are defined as flaws, loopholes, oversights, or errors that can be exploited. One could argue that weak law enforcement, lack of background checks, and the soft-target nature of schools all qualify as vulnerabilities. The problem is that none of these have changed significantly over the last 20 years so it’s difficult to attribute the increased risk to a rise in vulnerabilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Threats are defined as any natural or man-made event that could have some type of negative impact on the organization. In this context the threat would be the shooting act itself. Guns, people, and laws are not events therefore, cannot easily be labeled as threats. Even if one tried to make the case that they are threats, there has not been a significant increase in the number of guns, students, or laws in the U.S. over the last 20 years so they cannot logically be factors that have increased the overall risk. I propose that there is one important event, or trend, that has changed over the last 20 years and can be considered an indirect threat resulting in the increasing risk of school shootings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Today it seems anyone and everyone can become an instant celebrity. Starting in the mid-90’s with “reality” TV to the YouTube and Twitch contributors today, ordinary people can do in minutes what used to take professionals years to accomplish. News and social media have enabled the spread of information at light speed and promote both good and nefarious agendas. People seeking fame and wanting to feed their narcissism understand how easy it is to become a household name. To demonstrate this I encourage anyone to go out on the street and ask random people to name three school shooters or three vice presidents and see what happens.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; The rise of social media and the speed at which news (good, bad, real ,or fake) is promulgated is arguably a major factor in the risk of school shootings. The real question now is, how do we manage that?&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 02:15:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10609#M958</guid>
      <dc:creator>DAlexander</dc:creator>
      <dc:date>2018-05-23T02:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10636#M961</link>
      <description>&lt;P&gt;Daniel (&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/912952905"&gt;@DAlexander&lt;/a&gt;),&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sensationalism as a contributor to bad action is an interesting and appealing hypothesis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As laws are implemented that require disclosure of hacks and breaches of corporate systems, do you think this will:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(a)&lt;/STRONG&gt; Increase the sensationalism, and therefore the number of people that attempt hacking and intrusions (e.g. Snowden/Manning imitators and copycats)?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(b)&lt;/STRONG&gt; Simply increase the awareness of a hidden statistic that was previously underrepresented in the media (that these types of events are prevalent, just not reported in the media)?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(c)&lt;/STRONG&gt; Other (Please Explain)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 15:21:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10636#M961</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-23T15:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10664#M965</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/912952905"&gt;@DAlexander&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;someone with no real-life experience in the U.S. attempting to chime in on a predominately American problem.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;this strikes me as very odd, often times a view from outside is just the thing to help isolate a problem, like comparing equivalent risk factors that are highlighted as potential causes for an issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; The Columbine High School massacre was the first major school shooting event in the U.S.&lt;/P&gt;&lt;P class="1527130480102"&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Depends on your definition of major, ignoring Kent State and Jacksonville in the 70s there were plenty of examples of this pre Columbine (look up "I don't like mondays" which oddly enough I learned about on the original CISSP forum,&amp;nbsp;I was however already a fan of&amp;nbsp;the boomtown rats)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Vulnerabilities are defined as flaws, loopholes, oversights, or errors that can be exploited. One could argue that weak law enforcement, lack of background checks, and the soft-target nature of schools all qualify as vulnerabilities. The problem is that none of these have changed significantly over the last 20 years so it’s difficult to attribute the increased risk to a rise in vulnerabilities.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I would&amp;nbsp;argue that the 2004 expiration of the 1994 Federal Assault Rifle Ban would qualify as a significant change in law enforcement status as far as legal access to a certain class of highly accurate, and deadly firearms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Even if one tried to make the case that they are threats, there has not been a significant increase in the number of guns, students, or laws in the U.S. over the last 20 years&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Actually, while the % of&amp;nbsp;households with firearms has declined, the number of firearms in the US has&amp;nbsp; roughly doubled since 1968 - estimated at ~300&amp;nbsp;million guns in all - 101 guns per 100 people.&amp;nbsp; As the population has gone up by ~22% I think it would be reasonable to&amp;nbsp;extrapolate that the&amp;nbsp;population of&amp;nbsp;any given&amp;nbsp;selection of "likely shooters"&amp;nbsp; has probably increased roughly the same amount, even if active shooter ages only represented 10% I would still call that a significant increase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;News and social media have enabled the spread of information at light speed and promote both good and nefarious agendas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; The rise of social media and the speed at which news (good, bad, real ,or fake) is promulgated is arguably a major factor in the risk of school shootings. The real question now is, how do we manage that&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I think your on to something here, tho I think you've completely missed the root cause.&amp;nbsp;&amp;nbsp;Since 1982 approximately 55% of mass shootings were committed by white males (i had to do the math, I give myself a couple of points margin of error)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, rule #1, when analyzing data there is an absolute requirement to get accurate data -&amp;gt; more guns, more people who might be a larger threat if they have access to guns.&amp;nbsp; We'll ignore the issues around medical support, the&amp;nbsp;ignorance of blaming autism or ritalin.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Social media has certainly brought a lot of things to the masses faster than ever before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like a white male president who constantly blows the dog whistles of&amp;nbsp;xenophobia (immigrants are animals, muslims are terrorists) mysoginy (grabbed them by the...), racism (Mexican judge can't be impartial, nazis and white supremacists are fine people), anti-lgbtq (none in his military, thanks), attacks the first amendment, BLM, and peaceful protests, lies pathologically&amp;nbsp;etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like the state sponsored executions of people of color that are caught on tape but result in no justice for the executioners.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like the CEOs of home depot, or Amazon, or&amp;nbsp;Walmart&amp;nbsp;whose companies pay comparatively no taxes, and get rich while the folks working in the stores have to rely on welfare to get by&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like the countless examples of religious people&amp;nbsp;in positions of power&amp;nbsp;abusing children and getting sheltered by the church itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Convicted thugs who ignore the constitution and their promise to serve it , who are sexual predators, racists,&amp;nbsp; &amp;amp; child molesters&amp;nbsp;(Roy Moore is just the tip of the iceberg) RUNNING FOR LEGISLATURE, and receiving support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could go on, but you probably get the point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Money goes to the rich, instead of to schools, or medical programs, or food for the hungry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suddenly (in the last few years) we've seen a distinct uptick in (typically ignorant by definition) white male assaults on schools, on minorities, on those who don't believe in the same god.&amp;nbsp; Because they were turned down for a date, or hate people of color...&amp;nbsp; &amp;nbsp; Why do they act?&amp;nbsp; Why not? The state itself shows us that this behavior is ok.&amp;nbsp; The president needs his evangelical base too much to clearly and obviously disavow the KKK and white supremacy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So&amp;nbsp;what are the actual contributing Risk Factors?&lt;/P&gt;&lt;P&gt;More people?&amp;nbsp; Definitely. we can't control&amp;nbsp;population, but could probably mitigate some of the risk with supports, money for better schools (smaller classes, more tangential support), help for the poor, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More Guns? Definitely.&amp;nbsp; Can't seem to get decent legislation passed since 1994 tho, particularly with the NRA purchasing our legislative branch at will.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Social Media? Definitely.&amp;nbsp; The down side of getting to&amp;nbsp;raise awareness about&amp;nbsp;the things that need to be addressed, is that the sociopaths may take it as calcifying their belief that they, like LE system, the government, the CEOs (who, hmm - are all predominantly white males) can do what they want in the US - those other people are animals, or heathens, or worth less as a group than anything else our government spends money on&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;White Males?&amp;nbsp; Statistically, for sure.&amp;nbsp; Certainly there are other causative factors, but ignorant white males with easy access to guns seems to be a large part of this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh and tho I haven't analyzed the data, seems like canada is better at a whole lot of those things&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 03:53:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10664#M965</guid>
      <dc:creator>Dain</dc:creator>
      <dc:date>2018-05-24T03:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10669#M966</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Based on your response, I am concerned that I may have written my post in such a way that led readers to, as they say, “miss the forest for the trees.” My response to the original post was intended to simply propose a hypothesis about &lt;STRONG&gt;&lt;EM&gt;one&lt;/EM&gt;&lt;/STRONG&gt; of many &lt;STRONG&gt;&lt;EM&gt;possible&lt;/EM&gt;&lt;/STRONG&gt; factors contributing to the increased risk of school shootings and tie that to risk management as a whole. The ultimate goal was to continue the discussion on the risk management process by following a thread&amp;nbsp;about a topic that many (in the U.S. and elsewhere) are familiar with. That said, I have two main comments about your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; First, you described your “Rule #1” then continued your post by not adhering to that same rule. For instance, who validated the race and gender of each of the shooters since 1982 and how? Was the information gathered from a survey that mandates respondents only check one box or could they check multiple boxes? Was it determined by looking at their social media pictures and assigning a race and gender based on appearance? Were any of the shooters potentially born a different gender? Statistics are like news sources themselves…one must account for any bias before accepting them as valid. Unfortunately, (and not implying this is you) most consumers of statistics don’t have the time or knowledge of the science behind statistics to validate what they hear from the talking heads on [**insert news outlet here**] as accurate. This is why I did not present any statistics but rather my perception of what has changed over the last two decades when mass-shooting events have become more frequent. This is also why I will not lengthen this response by refuting your statistical sources including your final offensive claim regarding white males being “statistically” a risk factor (FWIW, I am not even a member of that statistical category and find that claim racist).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Second, one cannot simplify the cause to a problem as complex as what we are discussing here with a simple all-encompassing solution. As technicians, we are all naturally drawn to the binary, yes or no, on or off answers. If the risk were as simple as “white males are the problem” then we should be able to mitigate the risk with an access control like we do when “inbound port 80 traffic is the problem.” Unfortunately, the problem is much more complex than race and it wouldn’t have done anything to prevent the actual earliest school massacre in the U.S. (which I suppose I should have used as an example). Look up “Enoch Brown schoolhouse massacre 1764” for an example with more than twice the deaths as Kent State and, by the way, &lt;STRONG&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;/STRONG&gt; committed by a white male and well before the current U.S. president was even born.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Ultimately, I feel this thread has highlighted an important aspect to both&amp;nbsp;society and information security. We cannot apply a simple fix to a complex problem and expect it to be a perfect solution. We cannot apply a blanket policy that may work in another country to the U.S. and expect it to prevent all school tragedies. Likewise, we cannot blindly apply a security patch that worked in a Microsoft lab to a production environment and expect it to work flawlessly. What we can do is watch trends, assess risks, and know our systems.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 07:14:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10669#M966</guid>
      <dc:creator>DAlexander</dc:creator>
      <dc:date>2018-05-24T07:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10670#M967</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/723530429"&gt;@Baechle&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Great questions! I think all three options you presented are valid however, if I had to pick either (a) or (b) then I’d lean towards (b) “Simply increase the awareness of a hidden statistic that was previously underrepresented in the media (that these types of events are prevalent, just not reported in the media).” I’ll suggest a candidate for (c) in a moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I agree less with (a) because while these laws may lead to increased sensationalism of the acts themselves, it would probably not be the primary motivation for people to begin maliciously hacking others. The hypothesis I proposed was that the act of making mass-shooters instant celebrities is contributing to increased risk of future mass-shootings. Unlike those types of events however, nefarious online actors typically want to avoid the spotlight and are hardly ever named in the media.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Considering all phases of a cyber-attack require &lt;STRONG&gt;&lt;EM&gt;not &lt;/EM&gt;&lt;/STRONG&gt;being detected then fame would seem to be the last thing they’d want. The only place I suspect hackers would want notoriety is underground where, much like street gangs, they are known by nicknames and symbols that the general public cannot make sense of. I mentioned 4chan to a relative of mine once and she thought it was a new drink at Starbucks. If they do indeed want notoriety then it still doesn’t convince me that it would increase the number of people attempting hacks and intrusions. The media, and often the law enforcement personnel investigating the crimes, can rarely attribute cyber-crimes to specific perpetrators until the event itself is ancient history (days to weeks in today’s short-term public interest capacity…unless it’s a Russia investigation – sorry, couldn’t resist). That in itself would seem to turn the glory-hounds off.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; The (c) that I&amp;nbsp;envision is actually a positive result of the new laws. I think that by publicizing breaches it will motivate executives to invest more in information security, motivate information security professionals to invest more in their own craft, and motivate the tech industry as a whole to develop products in a more security-oriented manner. Shame, like narcissism, is a powerful motivator&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 07:29:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10670#M967</guid>
      <dc:creator>DAlexander</dc:creator>
      <dc:date>2018-05-24T07:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10688#M973</link>
      <description>&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/912952905"&gt;@DAlexander&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&amp;nbsp;&amp;nbsp; I agree less with (a) because while these laws may lead to increased sensationalism of the acts themselves, it would probably not be the primary motivation for people to begin maliciously hacking others. The hypothesis I proposed was that the act of making mass-shooters instant celebrities is contributing to increased risk of future mass-shootings. Unlike those types of events however, nefarious online actors typically want to avoid the spotlight and are hardly ever named in the media.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I think that this comment may highlight one of the fundamental complexities in doing risk management.&amp;nbsp; We rely too much on biases or popular media concepts of the threats we are attempting to mitigate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I concur that for several modes of attack (such as theft of intellectual property or credit card data over the Internet) the longer the attack stays undiscovered, the higher chances of both success and illicit usability of the stolen information.&amp;nbsp; However, when attacks eventually surface, notoriety for orchestrating the attack doesn't just stay within the shadows of the Dark Web.&amp;nbsp; Based on a brief survey of news releases and interviews by Insider Threats, I hadn't found one that stated they believed they were going to get away with it.&amp;nbsp; (&lt;STRONG&gt;If someone finds an article or an interview with an noted Insider Threat actor that said they believed they weren't going to get caught, please reply with a link&lt;/STRONG&gt;!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take for example, "exfocus," one of the personalities wrapped up in the mirai botnet:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.nj.com/news/index.ssf/2017/12/inside_the_massive_cyber_scam_launched_by_a_kid_fr.html" target="_blank"&gt;http://www.nj.com/news/index.ssf/2017/12/inside_the_massive_cyber_scam_launched_by_a_kid_fr.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exfocus was well known as an independent personality even if his true identity would take longer to discover.&amp;nbsp; The fame and attention you garner as an alter ego is just as rewarding as if it were being attributed to a true identity.&amp;nbsp; Possibly more so in some cases for the ability to elude being identified in true name.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 14:09:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10688#M973</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-24T14:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10699#M975</link>
      <description>&lt;P&gt;Gentlemen,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of your statements in this discussion strike a chord resonating with me about the veracity of information feeding decision making.&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;Risk management&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;should be an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;objective process&lt;/EM&gt;, but occasionally we have to make estimates using&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;subjective information&lt;/EM&gt;.&amp;nbsp; There is a danger in using opinion when there is real data available, and then there is a further danger in misusing the real data in establishing a narrative.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first problem brought to bear in the recent exchange is that of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;Questionable Cause&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;(&lt;SPAN&gt;&lt;EM&gt;Concluding that one thing caused another, simply because they are regularly associated&lt;/EM&gt;).&amp;nbsp; As&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;pointed out initially and&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;&amp;nbsp;then highlighted, Canada is an example of a country with laws permitting personal firearms ownership but without comparable rates of school violence.&amp;nbsp; I suggest that this occurs as much in other risk management discussions, causing us to argue over a symptom or even a byproduct instead of the root cause.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The second problem brought to bear in this exchange is that of&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Ignoratio Elenchi&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;or commonly the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Red Herring&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;(Attempting to redirect the issue to another that the person doing the redirecting can better respond to), and&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;Causal Reductionism&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;(Assuming a single cause or reason when there were actually multiple causes or reasons) to reach a&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Just-in-Case&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;(Making an argument based on the worst-case scenario rather than the most probable scenario, allowing fear to prevail over reason) conclusion.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;&amp;nbsp;wrote:&lt;P class="1527174398784"&gt;So, rule #1, when analyzing data there is an absolute requirement to get accurate data -&amp;gt; more guns, more people who might be a larger threat if they have access to guns.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This hypothesis is not falsifiable because it is always speculative.&amp;nbsp; This particular scenario is one that I often see as the basis for why security professionals and their postulations are mistrusted.&amp;nbsp; Although there are more guns available,&amp;nbsp;a&amp;nbsp;regression analysis of events shows there is an overall decline in mass murder gun violence between 2006 and 2016 and significantly more of a decline in schools.&lt;SPAN&gt;&lt;A href="#_ftn1" target="_blank"&gt;[1]&lt;/A&gt;&amp;nbsp; This whole conversation diverts us from the analysis of the root cause&amp;nbsp;question: "How do we detect and prevent manifestation of the violent Insider Threat, who may resort to violence regardless of the instrument chosen to implement their actions."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I propose that a better hypothesis would be, "Do more guns equate to an increase in mass murder violence, including and especially at schools?"&amp;nbsp; Since the answer is, "No," then we should temporarily eliminate this as a&amp;nbsp;&lt;EM&gt;root cause&lt;/EM&gt;&amp;nbsp;and leave it in the&amp;nbsp;&lt;EM&gt;contributing factor&lt;/EM&gt;&amp;nbsp;pile.&amp;nbsp; Mitigating against&amp;nbsp;&lt;EM&gt;contributing factors&lt;/EM&gt;&amp;nbsp;is a valid option in risk management however, it should be an alternative to an inability to mitigate against the&amp;nbsp;&lt;EM&gt;root cause&lt;/EM&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is a danger here in using&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Rationalization&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;(Offering an inauthentic excuse for the claim because we know the real reasons are embarrassing&amp;nbsp;to share or harsher than the manufactured ones given).&amp;nbsp; Using&amp;nbsp;&lt;EM&gt;Rationalization&lt;/EM&gt;&amp;nbsp;to focus on mitigating a&amp;nbsp;&lt;EM&gt;contributing factor&amp;nbsp;&lt;/EM&gt;is how we got to dumping a ridiculous&amp;nbsp;level of password complexity upon users rather than admitting as security professionals were failing to properly protect password databases and authentication systems.&amp;nbsp; The&amp;nbsp;likely result of mitigating against&amp;nbsp;&lt;EM&gt;contributing factors&amp;nbsp;&lt;/EM&gt;instead of the&amp;nbsp;&lt;EM&gt;root cause&amp;nbsp;&lt;/EM&gt;as a result of&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Rationalization&lt;/EM&gt;&amp;nbsp;is&amp;nbsp;in a repeat catastrophic&amp;nbsp;(violent) event using another instrument or approach.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm sorry&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;, but the remainder of your facts appear to be more collisions of&amp;nbsp;&lt;EM&gt;Questionable Cause&lt;/EM&gt;&amp;nbsp;leading to&amp;nbsp;&lt;EM&gt;Rationalization&lt;/EM&gt;&amp;nbsp;(the bad kind).&amp;nbsp; If we are going to continue to use Insider Threat violence as a hypothetical case study, could you please reference the basis for your argument?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In response to&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/912952905"&gt;@DAlexander&lt;/a&gt;, I heard/read a National Public Radio article about school violence in America.&amp;nbsp; From my memory, they stated there are approximately 1300 deaths per year in the United States.&amp;nbsp; If that statistic is true, then only a minority (possibly the most sensational?) of them appear to be making the news.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Eric B.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="#_ftnref1" target="_blank"&gt;&lt;SPAN&gt;[1]&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Allie Nicodemo &amp;amp; Lia Petronio,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;Schools are safer than they were in the 90s, and school shootings are not more common than they used to be, researchers say&lt;/U&gt;, Northeastern University News (Feb 26, 2018), Retrieved from, &lt;A href="https://news.northeastern.edu/2018/02/26/schools-are-still-one-of-the-safest-places-for-children-researcher-says/" target="_blank"&gt;https://news.northeastern.edu/2018/02/26/schools-are-still-one-of-the-safest-places-for-children-researcher-says/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 16:33:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10699#M975</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-24T16:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10700#M976</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dain,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Actually, while the % of&amp;nbsp;households with firearms has declined, the number of firearms in the US has&amp;nbsp; roughly doubled since 1968 - estimated at ~300&amp;nbsp;million guns in all - 101 guns per 100 people.&amp;nbsp; As the population has gone up by ~22% I think it would be reasonable to&amp;nbsp;extrapolate that the&amp;nbsp;population of&amp;nbsp;any given&amp;nbsp;selection of "likely shooters"&amp;nbsp; has probably increased roughly the same amount, even if active shooter ages only represented 10% I would still call that a significant increase.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;No, that's not a reasonable extrapolation unless you have the results of studies to back it up.&amp;nbsp; You have to do the studies and the math.&amp;nbsp; Has the rate of active shooter incidents increased by 22%, offset by the percentage of households that have declined in overall gun ownership?&amp;nbsp; Otherwise it's just&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Wishful Thinking&lt;/STRONG&gt;&lt;/EM&gt; (&lt;SPAN&gt;When the desire for something to be true is used in place of/or as evidence for the truthfulness of the claim).&amp;nbsp; If we're just making up statistics, it could also be considered&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Lying with Statistics&lt;/STRONG&gt;&lt;/EM&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 17:05:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10700#M976</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-24T17:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10767#M988</link>
      <description>&lt;P&gt;good point, the stats I pulled were from various non-partisan gov't sources (and generally were close enough from disparate sources to suggest reasonable expectation of validity) . Were I, say referencing them for a College Paper, I doubt my 10 min of bouncing round the interwebs would count for much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The shooter race stats were LE analysis based on I believe observation of those committing the crime, again probably not exactly 1st level reference material, but it did seem to jive across multiple sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also agree that theres no easy solution, much like IT.&amp;nbsp; A firewall (or bullet proof glass) only protects against certain threats, there needs to be multiple mechanisms to address the full scope of risk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now where have I heard that before?&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 03:20:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10767#M988</guid>
      <dc:creator>Dain</dc:creator>
      <dc:date>2018-05-25T03:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10768#M989</link>
      <description>&lt;P&gt;I was replying specifically to the assertion that the population hasn't changed in 20 years, it definitely has, and in a statistically significant way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that affect risk? maybe, maybe not, but the original assertion that the population was the same was incorrect and could not be used for risk analysis in anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i had studies to back up the extrapolation that a 20% overall population increase is likely to translate to a statistically significant increase in a portion of that population I wouldn't need to extrapolate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually would that be interpolating?&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 03:32:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10768#M989</guid>
      <dc:creator>Dain</dc:creator>
      <dc:date>2018-05-25T03:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10783#M992</link>
      <description>&lt;P&gt;Dain,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;&amp;nbsp;wrote:&lt;/P&gt;&lt;P&gt;If i had studies to back up the extrapolation that a 20% overall population increase is likely to translate to a statistically significant increase in a portion of that population I wouldn't need to extrapolate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually would that be interpolating?&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I wasn't arguing semantics about the use of the word extrapolate.&amp;nbsp; I was saying that extrapolation was an unsound practice given that there are metrics available that tell you &lt;STRONG&gt;(1)&lt;/STRONG&gt; how much the population has grown, and &lt;STRONG&gt;(2)&lt;/STRONG&gt; how many active shooters there were in prior years, including by age, ethnicity, and gender.&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;EDIT&lt;/STRONG&gt; My apologies - I apparently was saying that your metrics were not extrapolation based upon my understanding.&amp;nbsp; My understanding of extrapolation assumes that there was an underlying set of metrics that was used, and then an estimate was made where no metrics were available.&amp;nbsp; In this case, metrics were available, they simply weren't consulted.&amp;nbsp; So instead, this was more like a "WAG" than an extrapolation.&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;/EDIT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact, I think you would be hard pressed to find a study that proves your example.&amp;nbsp; The population has increased, but the&amp;nbsp;number of shooters has more or less stayed steady, if not declined.&lt;SPAN&gt;&lt;A href="#_ftn1" target="_blank"&gt;[1]&lt;/A&gt;&amp;nbsp; The end result is a trend pointing to an overall decline in the percentage of shooters compared to the population.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;EDIT&amp;nbsp;&lt;/STRONG&gt;&lt;STRIKE&gt;Specifically&lt;/STRIKE&gt; Throughout this conversation,&amp;nbsp;&amp;nbsp;I was hypothesizing a link between the process of &lt;STRIKE&gt;extrapolation&lt;/STRIKE&gt; the WAG of risk metrics by security professionals and the very reason that there is an apparent issue with&amp;nbsp;security professionals risk metric input being disregarded by organizational leaders.&amp;nbsp; I propose that &lt;STRIKE&gt;extrapolation&lt;/STRIKE&gt; WAGs are overused, potentially widely abused as being substitutes for extrapolation, and often way off an accurate estimate.&amp;nbsp; &lt;STRONG&gt;/EDIT&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;I was replying specifically to the assertion that the population hasn't changed in 20 years, it definitely has, and in a statistically significant way.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes.&amp;nbsp; That is supported by research.&lt;A href="#_ftn1" target="_blank"&gt;&lt;SPAN&gt;[2]&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;Does that affect risk? maybe, maybe not, but the original assertion that the population was the same was incorrect and could not be used for risk analysis in anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I concur.&amp;nbsp; That was a false premise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="#_ftnref1" target="_blank"&gt;&lt;SPAN&gt;[1]&lt;/SPAN&gt;&lt;/A&gt; Sandra L. Colby &amp;amp; Jennifer M. Ortman, &lt;U&gt;Projections of the Size and Composition of&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;the U.S. Population: 2014 to 2060&lt;/U&gt;, United States Census Bureau 2 (Mar 2014), Retrieved from &lt;A href="https://www.census.gov/content/dam/Census/library/publications/2015/demo/p25-1143.pdf" target="_blank"&gt;https://www.census.gov/content/dam/Census/library/publications/2015/demo/p25-1143.pdf&lt;/A&gt;; Emma Fridel, &lt;U&gt;A Multivariate Comparison of Family, Felony, and Public Mass Murders in the United States&lt;/U&gt;, Northeastern University (Nov 8, 2017) Retrieved from, &lt;A href="http://journals.sagepub.com/doi/abs/10.1177/0886260517739286" target="_blank"&gt;http://journals.sagepub.com/doi/abs/10.1177/0886260517739286&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="#_ftnref1" target="_blank"&gt;&lt;SPAN&gt;[2]&lt;/SPAN&gt;&lt;/A&gt; Colby &amp;amp; Ortman &lt;EM&gt;Supra&lt;/EM&gt; note 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 15:03:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10783#M992</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-25T15:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10785#M993</link>
      <description>&lt;P&gt;I think your point on misunderstanding (was it your point?) is getting proven&amp;nbsp;well in this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wasn't actually pointing to the population of --&amp;gt; active shooters &amp;lt;-- increasing&amp;nbsp;based on population, I was suggesting a potentially reasonable correlation between overall population increase and the (possibly) reasonable assumption that a 20% population increase would also show a statistically relevant increase in the population of&amp;nbsp;individuals representative of "at risk of becoming active shooters" (e.g. for the sake of argument lets say statistically 98% that group is 14-20 year old males&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Might be worthwhile to start a new thread with your thoughts on the issues that exist in InfoSec communicating risk to the business, where hard numbers are required (and available*)&amp;nbsp; I would definitely be interested in reading it w/o the, err, overhead / confusion of relating specifics here back to the original thread and various points we've all made.&amp;nbsp;&amp;nbsp; I seem to be doing&amp;nbsp;a pretty poor job of getting my points across with reference to the original thoughts, based on&amp;nbsp;some of the replies.&amp;nbsp; I was looking at this much more as a discussion on the specific points of Robs original post, while your take seems to be much more holistic (I think someone else pointed out this discrepancy as well, may well&amp;nbsp;have been you)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* While I do agree with you that hard numbers and&amp;nbsp;trusted source data (we all have to agree e.g. on source validity) as well as an agreed upon std for vulnerability criticality (cvss for instance) and asset value is a must in&amp;nbsp;any business minded risk analysis, I also believe that we are still very&amp;nbsp;much in the infancy of being able to build reliable "infosec actuary tables" which to some degree necessitates reasonable interpolation and extrapolation of existing data sets, as well as accepting some items as simple reality (if you don't practice&amp;nbsp;at least a baseline level of good security you will be compromised in some way seems like a given)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/d&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 15:32:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10785#M993</guid>
      <dc:creator>Dain</dc:creator>
      <dc:date>2018-05-25T15:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10791#M995</link>
      <description>&lt;P&gt;Dain,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/726954773"&gt;@Dain&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I think your point on misunderstanding (was it your point?) is getting proven&amp;nbsp;well in this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, that was one of my points.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;Might be worthwhile to start a new thread with your thoughts on the issues that exist in InfoSec communicating risk to the business, where hard numbers are required (and available*)&amp;nbsp; I would definitely be interested in reading it w/o the, err, overhead / confusion of relating specifics here back to the original thread and various points we've all made.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We may be able to do that down the road.&amp;nbsp; I believe that the emotional impact of the "school shooter" theme in this conversation is wearing off, and we're starting to reach a point where we're having a worthwhile and reasonable talk about this - in the context of &lt;STRONG&gt;Violent&amp;nbsp;Insider Threat Risk Management&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that this conversation is very difficult to have, precisely because it's emotionally charged (people that want guns, people that want gun control, etc.) and that detracts from the underlying professional conversation.&amp;nbsp; In my personal opinion, I think we are doing a good job at having (or at least starting to have) a difficult conversation.&amp;nbsp; I don't think we should run away or turn our backs on that.&amp;nbsp; It's precisely this exercise, having a professional debate around a (emotionally, not technically) difficult topic, that is a skill we all need to continue to develop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;I wasn't actually pointing to the population of --&amp;gt; active shooters &amp;lt;-- increasing&amp;nbsp;based on population, I was suggesting a potentially reasonable correlation between overall population increase and the (possibly) reasonable assumption that a 20% population increase would also show a statistically relevant increase in the population of&amp;nbsp;individuals representative of "at risk of becoming active shooters" (e.g. for the sake of argument lets say statistically 98% that group is 14-20 year old males&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Ok.&amp;nbsp; It's one of those days.&amp;nbsp; I forgot to address this component.&amp;nbsp; This argument is a self-fulfilling prophecy.&amp;nbsp; &lt;EM&gt;More people are at risk of potentially becoming active shooters because there are more people&lt;/EM&gt;&amp;nbsp;- is not falsifiable, in other words, not testable.&amp;nbsp; If we were to remove the &lt;EM&gt;potentially&lt;/EM&gt; and&amp;nbsp;change this hypothesis to be, &lt;EM&gt;In an increasing population, more white males aged 14-20 are at risk of becoming active shooters&amp;nbsp;&lt;/EM&gt;- we can actually test this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can go back and look at the factors that led the cohort of white males aged 14-20 who were active shooters and evaluate what contributed to their decision to become violent.&amp;nbsp; Then we can take those factors and look for them in a statistical cross section over a few years of all white males aged 14-20 to see if those factors increased or decreased in correlation with the number of shooters in that group.&amp;nbsp; If these factors did in fact correlate, then we can state that these are tentatively relevant risk factors.&amp;nbsp; Finally, we can develop detective measures that then look for those risk factors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem that I see, is that folks in the media are relying up rhetoric and speculation rather than actually conducting this and similar studies.&amp;nbsp; The list of causes in&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;'s original post appeared to me to be an example of how we reach bad conclusions, and thus risk management decisions.&amp;nbsp; I was merely extending his original thought of how we might be able to turn that around - and drawing similarities for where this causes problems in other risk management scenarios.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/EDIT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;I was looking at this much more as a discussion on the specific points of Robs original post, while your take seems to be much more holistic (I think someone else pointed out this discrepancy as well, may well&amp;nbsp;have been you)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We are currently standing on the precipice of a cultural shift in how&amp;nbsp;&lt;EM&gt;Insider Threats&lt;/EM&gt; are detected and managed; and like it or not a hearty sum of that burden is being thrown at IT Security professionals.&amp;nbsp;&amp;nbsp;&lt;EM&gt;Insider Threat&lt;/EM&gt; detection and mitigation&amp;nbsp;has existed for as long as people have gathered together in organization.&amp;nbsp; In modern times, it has rested in corporate and nation-state Counterintelligence functions until there was laser tight media focus on the exfiltration and destruction of electronic data.&amp;nbsp; Practically overnight it became an IT Security problem, when before IT Security was simply one input to the overall&amp;nbsp;&lt;EM&gt;Insider Threat&lt;/EM&gt; strategy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, like it or not protecting a school from a shooter is at least partially an Information Technology Security Risk Management discussion.&amp;nbsp; If not, then IT Security Pros should be ready to defend why it's not.&amp;nbsp; If we're willing to accept that it is, then IT Security Pros should be skilled at having this emotionally charged conversation diplomatically and be ready to dive into the risk metrics rather than WAG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In My Humble Opinion...&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 17:00:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10791#M995</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-25T17:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10794#M996</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/723530429"&gt;@Baechle&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We are currently standing on the precipice of a cultural shift in how&amp;nbsp;&lt;EM&gt;Insider Threats&lt;/EM&gt; are detected and managed; and like it or not a hearty sum of that burden is being thrown at IT Security professionals.&amp;nbsp;&amp;nbsp;&lt;EM&gt;Insider Threat&lt;/EM&gt; detection and mitigation&amp;nbsp;has existed for as long as people have gathered together in organization.&amp;nbsp; In modern times, it has rested in corporate and nation-state Counterintelligence functions until there was laser tight media focus on the exfiltration and destruction of electronic data.&amp;nbsp; Practically overnight it became an IT Security problem, when before IT Security was simply one input to the overall&amp;nbsp;&lt;EM&gt;Insider Threat&lt;/EM&gt; strategy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, like it or not protecting a school from a shooter is at least partially an Information Technology Security Risk Management discussion.&amp;nbsp; If not, then IT Security Pros should be ready to defend why it's not.&amp;nbsp; If we're willing to accept that it is, then IT Security Pros should be skilled at having this emotionally charged conversation diplomatically and be ready to dive into the risk metrics rather than WAG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;100% agreed - I think its extremely relevant based not only on the need for good data, but the lack of testable data as it relates to a specific risk factor / vulnerability.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll also happily concede the emotional piece, with 4/5 of my immediate family at a school everyday I get skittish when pundits on either side posit ridiculous tripe as root cause etc. (to Robs original post)&amp;nbsp;the capability to rationally carefully discuss, is in this instance, something I could easily have worked harder at. (doesn't help that my usual communication style&amp;nbsp;has been&amp;nbsp;described nicely as blunt)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was responding more from a perspective of "what could possibly be reasonable risk factors?"&amp;nbsp; preferably ones that could be addressed in some way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much like may InfoSec risk and vulnerability issues I think there comes a time (namely when we get into psychology) where its next to impossible to build a true scientific data set as we simply don't have the control groups, or the ability to demonstrably isolate individual contributing factors, let alone tangential factors which may decrease or increase the risk of an "at risk individual"&amp;nbsp;becoming a "perpetrator"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For instance we can easily prove/disprove the supposition that a 20% increase in overall population indicates a statistically significant increase in "at risk active shooter groups" (and could likely determine with fair accuracy what said increase is with a reasonable, experiential definition of said group) . However what we can't do scientifically is test the reasonable causative factors to determine which one is most likely to move an individual from "at risk" to "active shooter".&amp;nbsp; Thus the response becomes&amp;nbsp;more of an effort at minimizing the risk any way possible, based on the overal impact of the situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really do hate the UI, replying in email with simple cut and paste would be so much quicker, the small box and all or nothing quoting makes this take so much more time (tho mouse vs trackpad is still easier)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 17:19:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10794#M996</guid>
      <dc:creator>Dain</dc:creator>
      <dc:date>2018-05-25T17:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10796#M998</link>
      <description>&lt;P&gt;Dain,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let’s start here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;Much like may InfoSec risk and vulnerability issues I think there comes a time (namely when we get into psychology) where its next to impossible to build a true scientific data set as we simply don't have the control groups, or the ability to demonstrably isolate individual contributing factors, let alone tangential factors which may decrease or increase the risk of an "at risk individual" becoming a "perpetrator"&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I respectfully disagree that it’s nearly impossible to build a true scientific data set.&amp;nbsp; I will say that not many people are actually going out and building that data set.&amp;nbsp; Academically, the disciplines of psychology, sociology, and criminology are still very fractured and appear to just be crawling out of the pit of arguing over if either Jung or Freud was right.&amp;nbsp; This is opposed to admitting that there may be several different contributing factors relevant and applicable only to each individual case, and not to others.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then, Information Technology as a research discipline as opposed to an engineering discipline seems just taken its first yawning stretch of the morning.&amp;nbsp; I only know of one ongoing study of Insider Threat within the technology world, by Doctoral Candidate Jan Buitron (&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/986863095"&gt;@jbuitron&lt;/a&gt;)&amp;nbsp;(sorry for tagging you here if it was a distraction, but I wanted to give you props for tackling this topic).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will respectfully agree and amplify that we currently don’t have an effective ability to isolate individual contributing factors that indicate elevated risk.&amp;nbsp; As a society, it is my personal observation that we are willing to sit back and let media, superstition, and bias establish those factors instead of admitting to ourselves that we haven’t collected the data yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still have a problem with the foundation of your hypothesis.&amp;nbsp; It assumes that the risk factors (which we don’t know) are directly linked to the size of the population rather than fluctuate based on some other conditions (which we haven’t bothered to figure out yet).&amp;nbsp; I believe this is formally called a &lt;STRONG&gt;&lt;EM&gt;Regression Fallacy&lt;/EM&gt;&lt;/STRONG&gt;.&amp;nbsp; You can make every argument from it including the opposite to your position.&amp;nbsp; (a) With more people, there are more people in the world who are &lt;U&gt;not&lt;/U&gt; at risk of becoming violent. (b) With more people, there are more people at risk of spontaneously turning into carrots.&amp;nbsp; (c) With more people, there are more people at risk of making more people, and therefore potentially more carrots. (d) etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Care to take another stab at forming a hypothesis?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 18:31:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/10796#M998</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-05-25T18:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Risk management</title>
      <link>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/49208#M5649</link>
      <description>&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;Apologies for the late (belated reply). No need to apologize for tagging my studies in the Insider Risk\Insider Threat. I DID finish in June of 2018.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, life not only threw rocks in my way, it threw boulders. Boulders like to the 1000-plus homes burned to the ground in the cities of Superior and Louisville on 12-30-2021. I have still yet to publish my dissertation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep up the creative thought, and work,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best to you in all things,&lt;/P&gt;&lt;P&gt;Dr. Jan Shuyler Buitron&lt;/P&gt;&lt;P&gt;Doctorate of Computer Science in Cybersecurity, minor in Management&lt;/P&gt;&lt;P&gt;Master of Science in Cybersecurity&lt;/P&gt;&lt;P&gt;CISSP, MCSE, ITIL v2, v3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Senior Cybersecurity Systems Engineer\Lead)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 15:03:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Risk-management/m-p/49208#M5649</guid>
      <dc:creator>jbuitron</dc:creator>
      <dc:date>2022-01-21T15:03:58Z</dc:date>
    </item>
  </channel>
</rss>

