Sten Eikrem · @Storesteinen
43 followers · 67 posts · Server infosec.exchange

@fifonetworks I agree that the explanations in most certifications are bad. I'm currently working on and the language there is at the best of times unnecessary heavy and complicated.

I find it sad but understandable that respected online dictionaries can't tell the differences as well. Most folks can't. Its just a fact.

However would you agree that a common language and understanding of terms is crucial to have a meaningful common discussion on what to do and what to prioritise in ?

Unfortunately this is not my experience, even in the same organisations and teams.

This makes meaningful discussions in a topic already complex almost impossible.

From what I've come to understand over the years is that (and related (s)) is just one building block or component of . The other ones is the and / .

If you cannot describe these building blocks together, then you don't have a . You have something else, an , -thing . -list-of-things-todo

But please do not call it a .

When looking at the average this is what most of them contains just that - .

#crisk #risk #cyber #threat #threatactor #asset #control #vulnerability #lossevent #impact #issue #controldeviation #problem #a #something #riskregister #things

Last updated 2 years ago

Sten Eikrem · @Storesteinen
36 followers · 42 posts · Server infosec.exchange