“A security engineer who worked on the Quicktime patch to combat the Myspace worm has written a blog entry that suggests both companies have known about this for weeks, but nobody wanted to do anything about it unless some bad press came their way. If this is true, its a pretty disgraceful way to treat their userbase…”
This is business as usual for online business’. The risk is measured then mitigated according to how much impact it might have. If there is little or no press about a given moderated vulnerability that will cost them a lot of money, they will take little or no action.
Ready to actually get the RMF/ISSO job?
Go from reading about the Risk Management Framework to doing it — with the full video course, the books, and a community of GRC professionals taught by Bruce Brown (CISSP, CGRC).
Get the RMF ISSO Foundations course → Browse the RMF & GRC books Join the free GRC community
Leave a Reply