Wednesday, February 18, 2009

Four Grand Challenges in Trustworthy Computing

I just recently read the final report Four Grand Challenges in Trustworthy Computing and watched the panel discussion. I am quite interested in the grand challenge#3 (in slides or the grand challenge#4 in the panel discussion):

"Within 10 years, develop quantitative information-systems risk management that is at least as good as quantitative financial risk management."
"We cannot manage if we cannot measure: If you don’t have a measure you will either under-protect or overspend" The famous quote from Lord Kelvin (William Thompson) :
“When you can measure what you are speaking about, and express it in numbers, you know something about it; but when you cannot measure it, when you cannot express it in numbers, your knowledge is a meagre and unsatisfactory kind; it may be the beginning of knowledge, but you have scarcely, in your thoughts, advanced to the stage of science.”

Since the CRA Conference on"Grand Research Challenges in Information Security & Assurance" was in 2003, there has been some work in the academia on these challenges. They still exist today.

I also really like the following definition for the role of security from the presentation:

"Security is like adding brakes to cars. The purpose of brakes is not to stop you: it’s to enable you to go fast! Brakes help avoid accidents caused by mechanical failures in other cars, rude drivers, and road hazards. Better security is an enabler for greater freedom and confidence in the Cyber world."

There is also interesting vision as to why we need such challenges:
"Inspire creative thinking
– Encourage thinking beyond the incremental
• Some important problems require multiple approaches over long periods of time
• Big advances require big visions
– Small, evolutionary steps won’t take us everywhere we need to go"

No comments: