『Attributive Security』のカバーアート

Attributive Security

Attributive Security

著者: Martin Hopkins Maurice Smit
無料で聴く

今ならプレミアムプランが3カ月 月額99円

2026年5月12日まで。4か月目以降は月額1,500円で自動更新します。

概要

There is often a lot happening in the world of cyber security: new threats, new exploits and new products. Don’t get us wrong, there is a lot of cool technology, and we appreciate that. But, at least on the surface, a lot of the defensive advances look to be very bottom up and technology focused. It is easy to lose sight of the context, what matters to us that we want to protect, and yes even enable. Join us as we get together for unscripted conversations about a broad range of topics and relate them to cyber security. We’ll draw on various disciplines, and our own experiences, as we discuss ideas and practical approaches to tailored information security. We won’t be afraid to challenge one size fits all and best practice norms, or the misapprehension that bespoke security frameworks are infeasible for all but the biggest of enterprises. Be prepared to reimagine what an effective cyber security program can look like when it is engaged with and aligned to the business.Copyright 2026 Martin Hopkins, Maurice Smit 社会科学 経済学
エピソード
  • #15 Enterprise (Security)? Architecture
    2026/02/25

    Enterprise Architecture (EA) and Enterprise Security Architecture (ESA) are viewed as distinct functions with different predominant tools, frameworks and methodologies. ESA is maybe less consistently situated in business hierarchies – is it a part of EA or a more business facing part of security. What separates them and what unites them? If you had to draw a Venn diagram, would they intersect and what would live in that intersection?

    In this episode we discuss EA and ESA with Enterprise Architect Elise Luyckx. Have a listen to find out where we found common ground and where these disciplines could learn from each other or collaborate.

    続きを読む 一部表示
    1 時間 12 分
  • #14 Is Vertical Systemic Risk a One-Way Street?
    2022/10/01

    If you've studied SABSA to foundation level, you may recall how systemic risk navigates the domain model. If a risk materialises in a domain, the impact it has can act on the superdomain causing a risk event to occur there. Ok, simples right? Well Maurice was recently asked if this effect can occur in the opposite direction, i.e. from a domain to its subdomain. The search for a concrete example or a contradiction started.

    In this episode we consider this question which leads to further questions about the nature of hierarchy in the domain model and co-existent parallel domain models – but no quantum entanglement (yet). Have a listen and then join the debate, or if you have the answer put an end to it.

    続きを読む 一部表示
    40 分
  • #13 Blindsided by an Unknown Unknown
    2021/11/08

    With hindsight, declaring a risk an unknown unknown is often no more than an admission of a lack of foresight, a lack of imagination. How many risks that are actually realised were really inconceivable in advance? Risk identification is a process that is resource constrained, and reasonably so. But with more time, more perspectives, more insights, more intelligence the chances are you'd have identified the risk. Perhaps to do so would have not been cost effective; or you may have decided to limit analysis and not successfully managed an outlier risk. But to declare it an unknown unknown (after the fact) is rejecting an opportunity to learn. Is it not fatalistic to shrug one's shoulders and say "How could I have known"?

    In this episode we discuss Unknown Unknowns, along with their bedfellows Known Knowns, Known Unknowns and Unknown Knowns, and their place in the identification and management of business risks.

    続きを読む 一部表示
    37 分
まだレビューはありません