Re: computing the cost of incidents

From: lglover (lglover@shawus.com)
Date: 03/30/03


From: "lglover" <lglover@shawus.com>
Date: Sun, 30 Mar 2003 15:44:09 -0500


"sam bailey" <usenet@entropymedia.com> wrote in message
news:d1667b70.0303290906.ec1a432@posting.google.com...
> I'm doing some background research for an upcoming television program
> on computer security and in the process of reading all the interviews
> we've done with people in the field there's a wide variation in the
> damage estimates from more recent worms and things like slammer: from
> around hundreds of millions ($US) to hundreds of billions.
>
> I'm no expert on the matter but the higher-end numbers seem mighty
> inflated to me - they almost seem like they count the salary of
> everyone who's touched a system affected by the worm. I know there
> were some serious disruptions in the case of slammer (trading desks
> closed at financial institutions, atms, credit card clearing systems)
> but I can't see it being more than the GNPs of many small countries.
>
> can anyone point me towards some resource or method for estimating
> these sorts of things a bit more realistically? I understand nobody
> can really say for sure on these matters I feel like there must be
> some way to come up with a rough picture of it. or if I'm off base
> here and these numbers are indeed realistic that information would be
> a great help as well. I worry about this because in news stories on
> security issues they often understate some risks and overstate others
> - I'm just trying to bring a bit of balance to the process. I'll read
> the group here and the email address in the header is valid - any help
> would be much appreciated.
>
> thanks.
> sam bailey

try http://www.sans.org/rr/ for various articles on information security

-----= Posted via Newsfeeds.Com, Uncensored Usenet News =-----
http://www.newsfeeds.com - The #1 Newsgroup Service in the World!
-----== Over 80,000 Newsgroups - 16 Different Servers! =-----



Relevant Pages

  • The bugs stop here
    ... Nearly everything about the SQL Slammer was old. ... There was a patch to block Slammer ... "Use freely available security standards ... The government has many other security standards. ...
    (microsoft.public.security)
  • Re: The bugs stop here
    ... > Nearly everything about the SQL Slammer was old. ... There was a patch to block Slammer ... > that mandates that any software used in a national security setting must ... > The government has many other security standards. ...
    (microsoft.public.security)
  • ISO 27001 Newsletter: Edition 17 Released
    ... The latest issue of the newsletter covering the ISO information ... news and background with respect to the ISO security standards. ... Trials and Tribulations of an Information Security Officer ... Business Continuity Management: Preparation and Risk ...
    (comp.security.misc)
  • REVIEW: "The Information Security Dictionary", Urs E. Gattiker
    ... "The Information Security Dictionary", Urs E. Gattiker, 2004, ... %T "The Information Security Dictionary" ... The entry for Authentication does not list the ... listing is given for trade secrets or trade marks. ...
    (alt.computer.security)
  • The ISO 27001 Newsletter: Issue 18 Published
    ... news and background with respect to the ISO security standards. ... Trials and Tribulations of an Information Security Officer Part 2 ...
    (comp.security.misc)