<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Risk assessment science</title>
	<atom:link href="http://www.securitybalance.com/2009/05/risk-assessment-science/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitybalance.com/2009/05/risk-assessment-science/</link>
	<description>trying to bring balance to the Force</description>
	<lastBuildDate>Tue, 20 Apr 2010 03:58:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: Chris Hayes</title>
		<link>http://www.securitybalance.com/2009/05/risk-assessment-science/comment-page-1/#comment-240</link>
		<dc:creator>Chris Hayes</dc:creator>
		<pubDate>Thu, 21 May 2009 15:44:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitybalance.com/2009/05/risk-assessment-science/#comment-240</guid>
		<description>Hi Augusto. Assessing an issue for risk and modeling risk are two different things. Further complicating matters is when we need to aggregate the risk associated with numerous risk issues. The good news is that pretty much everything you have listed for “brings results that can [be] used to” – exists today. Actuaries and risk modelers have built these types of models for centuries. Just now are we seeing the same types of models being used for operational risk types.

As for a risk assessment methodology and tools that begin to model risk and show control effectiveness – I would recommend you review the FAIR methodology and Risk Management Insight’s toolset. You can also build you own modeling tools – but this is not a trivial task even for simple risk models.</description>
		<content:encoded><![CDATA[<p>Hi Augusto. Assessing an issue for risk and modeling risk are two different things. Further complicating matters is when we need to aggregate the risk associated with numerous risk issues. The good news is that pretty much everything you have listed for “brings results that can [be] used to” – exists today. Actuaries and risk modelers have built these types of models for centuries. Just now are we seeing the same types of models being used for operational risk types.</p>
<p>As for a risk assessment methodology and tools that begin to model risk and show control effectiveness – I would recommend you review the FAIR methodology and Risk Management Insight’s toolset. You can also build you own modeling tools – but this is not a trivial task even for simple risk models.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vicente Aceituno</title>
		<link>http://www.securitybalance.com/2009/05/risk-assessment-science/comment-page-1/#comment-239</link>
		<dc:creator>Vicente Aceituno</dc:creator>
		<pubDate>Thu, 21 May 2009 09:25:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitybalance.com/2009/05/risk-assessment-science/#comment-239</guid>
		<description>I really coudn&#039;t agree more with you.</description>
		<content:encoded><![CDATA[<p>I really coudn&#8217;t agree more with you.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
