07 April 2009

Safety Hazards and Security Threats

Blind adherence to methods without using professional judgment is commonplace across all work sectors.

Just because a system is out-of-date, not supported by the supplier or contains known security weaknesses, doesn't mean it has to be rebuilt or replaced.

An article in The Chemical Engineer April 2009, by Harvey Dearden, discusses professional judgement and reproduces the following statements from the UK Engineering Council's Code for Professional Conduct regarding risk issues:

Judgement is required to match the approach to the nature of the hazard and the level of risk. This might vary from a simple assessment to a formal safety case.

and:

Uncertainty is a feature of many aspects of risk management. Be aware of this, and use risk assessment methods as an aid to judgement, and not as a substitute for it.

The first statement could easily be re-written replacing "hazard" and "safety" with "threat" and "security" respectively. The second is equally true for assessing application security risks. However, in security engineering we do need to be aware of the lack of good statistical data to help form valid judgements.

Posted on: 07 April 2009 at 09:02 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Safety Hazards and Security Threats
http://www.clerkendweller.com/2009/4/7/Safety-Hazards-and-Security-Threats
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/4/7/Safety-Hazards-and-Security-Threats
Requested by 38.107.191.106 on Wednesday, 8 September 2010 at 00:47 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2010 clerkendweller.com