- BlackBerry Storm vs. the iPhone
- Digg's Kevin Rose: "We have to do better"
- Blogger warns: "Nortel doesn't make it out alive"
- Financial quagmire bringing out the scammers
- Verizon plays with the wrong e-mail addresses
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.
Does climate change have any relevance for information assurance and business continuity? My friend and colleague John Orlando, program director of the Master of Science in Business Continuity Management (MSBC) program at Norwich University, thinks so. Here's his contribution to the discussion.
* * *
I [John] had just gotten off the phone with one of the professors in our MSBC program. We were discussing the difficulty in measuring risk. Although business continuity programs are traditionally justified on grounds that the money spent will be well spent through prevention or mitigation of losses due to business disruptions, it is actually very difficult to assess risk accurately.
One problem is that people tend to overstate risks that have a psychological impact. For example, many people fear flying over driving, even though driving is the greater risk. People rank terrorism as a high risk, even though it is a much lower risk than accident or crime. We also tend to understate the danger of events that have not happened in a while.
No sooner had I hung up than an e-mail appeared from the university warning that there was a tornado watch for the area. On the way home that evening I told my carpool mates that tornados are not an issue in Vermont – as they are in Wisconsin, where I grew up – because mountains break them up. My wife and I have lived in Vermont for 15 and 20 years, respectively, and there has never been a tornado in Vermont in all the time we have lived in the state. I also told them that the instructions in the message were mostly wrong. Being from Wisconsin, I know tornados.
Talk about getting egg on one’s face! When I arrived home, there were police all over my neighborhood. Huge trees were ripped out, including a big one in our backyard that luckily missed the house. A house a few hundred yards from us had a tree take out its top floor and porch. It is not clear if an actual tornado hit our neighborhood, but a pre-tornado funnel cloud was sighted heading our way just before the 70 mph winds hit, which are the strength of a weak tornado.
The next day I went to a tornado Web site where I learned that some mountainous areas do get tornados, and most of what else I thought I knew about tornados was wrong.
M. E. Kabay, PhD, CISSP-ISSMP, is Program Director of the Master of Science in Information Assurance program at Norwich University.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment