Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wouldn't say it's the main focus, but this is an extremely valuable risk treatment. I would say it's underrated.

Too many orgs go into do or die mode and try to do everything and do it poorly. Accepting risk is a liability no person in authority ever wants to sign, even if it's accepting the risk of an earth destroying comet. They will ask you to do what you can instead, when you don't have enough resources to even begin implementing the needed controls.

Often in info sec governance literally the only way for us to get leadership to accept a realistic scope is to do as much risk transference as possible.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: