269 Followers
238 Following
33 Posts
BlogBlog @ www.securitydifferently.com
WorkDirector of GRC Security & Privacy @ LastPass
Is this thing still on ? I 

The job of GRC doesn’t stop when you write policies, communicate and make users “aware”. That’s table stakes.

It must include seeing through the changing of operational / business practice to reflect the intent of policy.

What you think the job is matters more than you think.

I’ll be talking with Mario Platt about Security Differently for platforms… and resilience engineering… and sociotechnical systems…

We are gonna have fun!

Join us at 4pm EST

https://www.youtube.com/watch?v=Y2D7gbyzyXQ&list=PLP5L2Mb-g_SRUa_nvjKn8xPpspQUsgOnl

Mario Platt and Jabe Bloom Platform Design and Security

YouTube

“We have a choice. We choose between self control, ill discipline, virtue and vice.

Self control must be observed physically, embodied mentally and must be rendered magisterially when our moment comes.

It’s our decision how this will look like, not once but a thousand times in life. Not just in the past, and in the future but right now, today.

What will it be ? Dependence or independence ? Greatness or ruin ?

Discipline is Destiny. It decides.

Will you choose it?”

- Ryan Holiday in ‘Discipline is Destiny’

Great management systems consider stakeholder bias and implement ways to avert it

One of the many reasons I’m a proponent of both risk analysis and threat modelling, ensuring they connect but aren’t overly prescriptive

Top-down meets bottom-up, but each isn’t bound by the other

“Losing is not always up to us, but being a loser is.

Being a quitter is. Saying “what the hell, why does this even matter”. That’s on us.

Throwing in the towel on a fight we clearly lost is one, throwing in the towel on fighting ? On your standards ? From that point forward ?

Now you’ve been beaten.”

- Ryan Holiday

Went searching for some info on Rasmussen's model and came across @norootcause's blog on it, so I'm obliged to repost:

https://surfingcomplexity.blog/2021/05/31/transgressing-the-boundaries-rasmussen-and-woods/

Transgressing the boundaries: Rasmussen and Woods

Surfing Complexity
Open Positions | Careers at Ping Identity

Explore exciting career opportunities at Ping Identity, a leader in the identity and access management industry.

“Being the boss, is a job.

Being a leader, is something you earn.

You get elevated to that plan by your self-discipline, by the moments of sacrifice like this where you take the hit or the responsibility on behalf of someone else”

- Ryan Holiday

If you perform or are interested in improving #GRC then @Madplatt's talk at #SREcon is a must watch.

He shares how GRC can improve based on approaches that SRE has already developed.

Excellent ideas!
https://www.youtube.com/watch?v=ZEeaLQUxvW4

SREcon22 EMEA - How Can SRE Help Security Governance? Sub-title: How to Unstuck GRC with SRE

YouTube