If you can manage to remove all (from the past, the present and future, known and unknown (and all points between)) vulnerabilities then there CAN NOT be any risks!
Does that well know information security saying "like kicking stoned puppies" become invalid as all blogs will be risk-less "Attacking this blog is probably like kicking stoned puppies"Also there will be no more security charlatans and security theatre
Also this can be applied to all risks (finance, crossing the road, etc)
And how to define it
There are no risks that anything…………………………………………....
…………………………………….……………………...does not happens
leading to no impact ………………………………………………………..
which does not need to be mitigated by anything…………………………..
Also if there is no threat it does not even matter is there are any vulnerabilities.
ReplyDeleteI remember a wise old ex-pert relating it to a man with a knife but did not want to stab anyone, so there is a vulnerability human skin that can be attacked with a knife......but I have forgotten the rest
So if risk is defined as R = V * I * T if any of T or I or V are 0 then R must be 0 there for QBT or is it QED ?
ReplyDelete