Full Disclosure
In my day job I am Solutions Architect for the McAfee Risk and Compliance Business Unit. Our products cover compliance management, risk management, IT security risk analysis, and a range of application and change control technologies.
[3/2/2010 note: when I wrote this article I worked for McAfee. I do, however, no longer. :)]
In a former life I evaluated complex, multidimensional data sets using models and metrics - I was a scientist performing quantitative analysis of noisy data. The result is that I've spent many years and a lot of energy thinking about and using models, metrics, and measurement. That background gives me certain views, opinions, and expectations.
Now that you know where I'm coming from let's talk about risk, measurements, metrics, and uncertainty. ;)
Click to read more ...