<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Risk / Threat vs. Risk Issue</title>
	<atom:link href="http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/feed/" rel="self" type="application/rss+xml" />
	<link>http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/</link>
	<description>Assessing, Articulating &#38; Quantifying Information Security Risk</description>
	<lastBuildDate>Mon, 31 Oct 2011 20:19:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Chris Hayes</title>
		<link>http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/#comment-359</link>
		<dc:creator><![CDATA[Chris Hayes]]></dc:creator>
		<pubDate>Tue, 27 Oct 2009 12:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=240#comment-359</guid>
		<description><![CDATA[Thanks for the comments everyone!

@M. Wallace - You should now be able to click on the image and it should open a new browser window and be easier to view. Thanks for catching that!]]></description>
		<content:encoded><![CDATA[<p>Thanks for the comments everyone!</p>
<p>@M. Wallace &#8211; You should now be able to click on the image and it should open a new browser window and be easier to view. Thanks for catching that!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M. Wallace</title>
		<link>http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/#comment-358</link>
		<dc:creator><![CDATA[M. Wallace]]></dc:creator>
		<pubDate>Tue, 27 Oct 2009 11:51:30 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=240#comment-358</guid>
		<description><![CDATA[I&#039;d like to noodle the diagram.  But I&#039;m over 40. The text on the diagram is below the &quot;greeking&quot; level.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;d like to noodle the diagram.  But I&#8217;m over 40. The text on the diagram is below the &#8220;greeking&#8221; level.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saso</title>
		<link>http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/#comment-357</link>
		<dc:creator><![CDATA[Saso]]></dc:creator>
		<pubDate>Mon, 26 Oct 2009 22:35:57 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=240#comment-357</guid>
		<description><![CDATA[Sounds much like the reasoning we used at my current employer to get everyone on the same page w.r.t. issues and risks; things to worry about and address and things that we can&#039;t influence one way or another: things to live with and monitor.

Ended up with the following definitions to make it easier for everyone to see where we&#039;re coming from:

risks: assessed (guesstimated) PLM and LEF. Not necessarily eventuating in the next 6 - 12 months even if their LEF hints at this;

issues: risks that are bound to come and bite you in the behind in the coming 6 - 12 months unless something is done about them right now. Stuff raised by auditors usually falls in this category. You ignore them at your own peril. (The quality of issues they raise is up for discussion, but ignoring them is usually not the smartest thing to do.)]]></description>
		<content:encoded><![CDATA[<p>Sounds much like the reasoning we used at my current employer to get everyone on the same page w.r.t. issues and risks; things to worry about and address and things that we can&#8217;t influence one way or another: things to live with and monitor.</p>
<p>Ended up with the following definitions to make it easier for everyone to see where we&#8217;re coming from:</p>
<p>risks: assessed (guesstimated) PLM and LEF. Not necessarily eventuating in the next 6 &#8211; 12 months even if their LEF hints at this;</p>
<p>issues: risks that are bound to come and bite you in the behind in the coming 6 &#8211; 12 months unless something is done about them right now. Stuff raised by auditors usually falls in this category. You ignore them at your own peril. (The quality of issues they raise is up for discussion, but ignoring them is usually not the smartest thing to do.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 10/26/2009 &#124; Infosec Ramblings</title>
		<link>http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/#comment-356</link>
		<dc:creator><![CDATA[Interesting Information Security Bits for 10/26/2009 &#124; Infosec Ramblings]]></dc:creator>
		<pubDate>Mon, 26 Oct 2009 19:40:58 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=240#comment-356</guid>
		<description><![CDATA[[...] on risk/threat vs risk issue. When does a risk or threat become a risk issue for your organization? Risk / Threat vs. Risk Issue &lt;&lt; Risktical Ramblings Tags: ( risk [...]]]></description>
		<content:encoded><![CDATA[<p>[...] on risk/threat vs risk issue. When does a risk or threat become a risk issue for your organization? Risk / Threat vs. Risk Issue &lt;&lt; Risktical Ramblings Tags: ( risk [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shrdlu</title>
		<link>http://risktical.com/2009/10/26/risk-threat-vs-risk-issue/#comment-354</link>
		<dc:creator><![CDATA[shrdlu]]></dc:creator>
		<pubDate>Mon, 26 Oct 2009 18:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://risktical.com/?p=240#comment-354</guid>
		<description><![CDATA[Very true.  You might say that &quot;risk&quot; = &quot;possibility&quot; while &quot;risk issue&quot; = &quot;probability worth paying attention to&quot; :-)

This is especially important when the elevation from &quot;risk&quot; to &quot;risk issue&quot; is being caused by something your organization (or its staff) is doing.]]></description>
		<content:encoded><![CDATA[<p>Very true.  You might say that &#8220;risk&#8221; = &#8220;possibility&#8221; while &#8220;risk issue&#8221; = &#8220;probability worth paying attention to&#8221; <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>This is especially important when the elevation from &#8220;risk&#8221; to &#8220;risk issue&#8221; is being caused by something your organization (or its staff) is doing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

