BigSnarf blog

Infosec FTW

Evidence based decision making – Instant access to diagnosis, treatment and prognosis

Wouldn’t it be nice to get snapshot of system RAM, MD5 of 100k HDD files, and 100mb PCAP and upload to “cloud” and get health status of box? Result: System is Trusted.  Infosec doesn’t have enough studies in defense research and attack research to help Infosec practitioners answer questions that easily. There are severe limits of the fields knowledge within Infosec.  I think there are systematic problems with Infosec and the industry. particularly information/data sharing. There isn’t a publicly available compendium to knowledge for us to query. Without these tools, Infosec is shooting from the hip, on “past intuition”.  Data-driven security will have to be more than metrics.

Learning from the study of medicine

In the above screenshot, is a tool doctors use called First Consult.  First Consult is an evidence-based clinical information resource for healthcare professionals. Designed for use at point of care, it provides instant, user-friendly access to the latest information on evaluation, diagnosis, clinical management, prognosis, and prevention. Data-driven security will have to be more than metrics.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: