BigSnarf blog
Infosec FTW
Evidence based decision making – Instant access to diagnosis, treatment and prognosis
Posted by on April 2, 2012
Wouldn’t it be nice to get snapshot of system RAM, MD5 of 100k HDD files, and 100mb PCAP and upload to “cloud” and get health status of box? Result: System is Trusted. Infosec doesn’t have enough studies in defense research and attack research to help Infosec practitioners answer questions that easily. There are severe limits of the fields knowledge within Infosec. I think there are systematic problems with Infosec and the industry. particularly information/data sharing. There isn’t a publicly available compendium to knowledge for us to query. Without these tools, Infosec is shooting from the hip, on “past intuition”. Data-driven security will have to be more than metrics.
Learning from the study of medicine
In the above screenshot, is a tool doctors use called First Consult. First Consult is an evidence-based clinical information resource for healthcare professionals. Designed for use at point of care, it provides instant, user-friendly access to the latest information on evaluation, diagnosis, clinical management, prognosis, and prevention. Data-driven security will have to be more than metrics.
