I really like the idea of forcing someone to almost sign that they accept the risk. Forces them to really think about it.And here is my answer:
One thing I'm curious about is whether there is such as thing as "risk fatigue" like you have "monitoring fatigue". So, the first few times you accept risk you do so with a heavy heart, but each time you do it and there are no perceived negative consequences, it gets a little easier. That is until the point when you're completely exposed and something bad does actually happen. Having said that, the alternative of not physically accepting the risk in some way is far worse IMO, and that by using something like Jira you can at least measure the ratio of fixed vs risk accepted over time. Hopefully it moves in the right direction!
A personal blog about: transforming Web Application Security into an 'Application Visibility' engine, the OWASP O2 Platform, Application/Data interoperability and a lot more
Showing posts with label RISK. Show all posts
Showing posts with label RISK. Show all posts
Thursday, 3 March 2016
JIRA RISK workflow handling of 'Risk Fatigue'
On a email thread related to Updated JIRA RISK workflow (now with a 'Fixing' State), I received this great question:
Subscribe to:
Posts (Atom)