<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Risk Convergence Frustrations</title>
	<atom:link href="http://risktical.com/2008/12/12/risk-convergence-frustrations/feed/" rel="self" type="application/rss+xml" />
	<link>http://risktical.com/2008/12/12/risk-convergence-frustrations/</link>
	<description>Assessing, Articulating &#38; Quantifying Information Security Risk</description>
	<lastBuildDate>Mon, 31 Oct 2011 20:19:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Tushar Pasrija</title>
		<link>http://risktical.com/2008/12/12/risk-convergence-frustrations/#comment-162</link>
		<dc:creator><![CDATA[Tushar Pasrija]]></dc:creator>
		<pubDate>Fri, 26 Dec 2008 08:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=128#comment-162</guid>
		<description><![CDATA[I have three points to share regarding risks:
a) Any risk identification or mitigation in any form should be the responsibility of the function where it exists or has been detected and is the accountability of the leadership which would be leading the area where the risk impact is bound to surface.
b) There are adequate simple and complex methodologies existing for identifying risks (mitigation, of course, depends on the people who want to act on these identified risks) but most of such identification exercises go bust because of excessive hype around the &quot;risk identification and mitigation planning exercise&quot; and what i call &quot;sleeping over a set of risks&quot;.
c)Attaching Dollar value to the risks sells it better but there are several risks which have cascading, jeopordising, and non-monetary impact and they should be (but mostly are not) treated with equal priority and gusto.]]></description>
		<content:encoded><![CDATA[<p>I have three points to share regarding risks:<br />
a) Any risk identification or mitigation in any form should be the responsibility of the function where it exists or has been detected and is the accountability of the leadership which would be leading the area where the risk impact is bound to surface.<br />
b) There are adequate simple and complex methodologies existing for identifying risks (mitigation, of course, depends on the people who want to act on these identified risks) but most of such identification exercises go bust because of excessive hype around the &#8220;risk identification and mitigation planning exercise&#8221; and what i call &#8220;sleeping over a set of risks&#8221;.<br />
c)Attaching Dollar value to the risks sells it better but there are several risks which have cascading, jeopordising, and non-monetary impact and they should be (but mostly are not) treated with equal priority and gusto.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

