<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exploring F.A.I.R. &#8211; Threats &#8211; Part 1</title>
	<atom:link href="http://www.infosecramblings.com/2009/03/09/exploring-fair-threats-part-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecramblings.com/2009/03/09/exploring-fair-threats-part-1/</link>
	<description>ramblings on various information security topics</description>
	<lastBuildDate>Tue, 07 Feb 2012 23:34:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: kriggins</title>
		<link>http://www.infosecramblings.com/2009/03/09/exploring-fair-threats-part-1/#comment-1920</link>
		<dc:creator>kriggins</dc:creator>
		<pubDate>Thu, 28 May 2009 02:16:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecramblings.com/?p=776#comment-1920</guid>
		<description>Thanks for the input and thoughts on the DFD&#039;s. My intent was to use the DFD to show simple intended application use cases at this point. I could extend that, but probably won&#039;t at this point.

The series will continue. I gave a talk on FAIR at Secure360 this month and that sucked up all the free time I had in preparation :) Of course, I will be able to use some of that info as we go forward with this series. 

I hope to get back to it in the next couple weeks as some other obligations settle down.

Thanks for reading!

-Kevin</description>
		<content:encoded><![CDATA[<p>Thanks for the input and thoughts on the DFD's. My intent was to use the DFD to show simple intended application use cases at this point. I could extend that, but probably won't at this point.</p>
<p>The series will continue. I gave a talk on FAIR at Secure360 this month and that sucked up all the free time I had in preparation <img src='http://www.infosecramblings.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Of course, I will be able to use some of that info as we go forward with this series. </p>
<p>I hope to get back to it in the next couple weeks as some other obligations settle down.</p>
<p>Thanks for reading!</p>
<p>-Kevin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bonvillain</title>
		<link>http://www.infosecramblings.com/2009/03/09/exploring-fair-threats-part-1/#comment-1919</link>
		<dc:creator>Bonvillain</dc:creator>
		<pubDate>Thu, 28 May 2009 02:04:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecramblings.com/?p=776#comment-1919</guid>
		<description>I actually haven&#039;t created tons of DFD&#039;s myself, but there were other use-cases at play in that architecture diagram that seem to be applicable if relating them to a risk analysis such as FAIR and ultimately to the threat analysis that it looks like you are about to perform. 
Maybe Phil can advise if you would want to document such things, or if the DFD is just intended to be applicable to intended web app functionality, vs. comprehensively diagram all possible use-cases. Regardless, as related by the swiss-cheese firewall policy, those remote users are just using Telnet, FTP and getting direct access to the database to perform their remote management in the absence of a dedicated solution. Seems like you may want to include those components in the DFD as well as they are certainly applicable to the threat analysis and ultimate loss event frequency right?

Hope you are continuing this series. I am just starting to do some research on FAIR and am enjoying the posts.</description>
		<content:encoded><![CDATA[<p>I actually haven't created tons of DFD's myself, but there were other use-cases at play in that architecture diagram that seem to be applicable if relating them to a risk analysis such as FAIR and ultimately to the threat analysis that it looks like you are about to perform.<br />
Maybe Phil can advise if you would want to document such things, or if the DFD is just intended to be applicable to intended web app functionality, vs. comprehensively diagram all possible use-cases. Regardless, as related by the swiss-cheese firewall policy, those remote users are just using Telnet, FTP and getting direct access to the database to perform their remote management in the absence of a dedicated solution. Seems like you may want to include those components in the DFD as well as they are certainly applicable to the threat analysis and ultimate loss event frequency right?</p>
<p>Hope you are continuing this series. I am just starting to do some research on FAIR and am enjoying the posts.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

