<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.11" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Turtles, BART, and Stock Trades</title>
	<link>http://www.cigital.com/justiceleague/2007/04/05/turtles-bart-and-stock-trades/</link>
	<description>The Cigital Software Security and Quality Blog</description>
	<pubDate>Mon, 13 Oct 2008 00:45:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.11</generator>

	<item>
		<title>by: Eric</title>
		<link>http://www.cigital.com/justiceleague/2007/04/05/turtles-bart-and-stock-trades/#comment-224</link>
		<pubDate>Fri, 06 Apr 2007 05:03:46 +0000</pubDate>
		<guid>http://www.cigital.com/justiceleague/2007/04/05/turtles-bart-and-stock-trades/#comment-224</guid>
					<description>Very interesting post ! 

I am working on an application risk classification system and one of the metric that we use to evaluate the risk is "competency of the application team". What do I mean by that ? When building a system, the architect/developers may decide to use a new technology that they are not familiar with. Evidently there will be a learning curve and this will impact the overall risk of the system. For example, nowadays you see many people moving their legacy app. to new platform (J2EE, .NET, etc.). That metric is hard to estimate. What's the risk reduction when you have used a technology twice, three time, more ?. We use an heuristic approach and consider the frequency of use with the number of technology. Scaling that metric with the system that we have reviewed before is also a good approach. I don't want to extend to much on this. But going back to your post I think the car industry is looking actively at computer backing up the driver. I have seen a prototype of alarm turning on when you get asleep while driving...There is one very popular..the GPS which actually killed a few people who took the GPS's voice as straight order: "Turn left !" (but there was not left to make).</description>
		<content:encoded><![CDATA[<p>Very interesting post ! </p>
<p>I am working on an application risk classification system and one of the metric that we use to evaluate the risk is &#8220;competency of the application team&#8221;. What do I mean by that ? When building a system, the architect/developers may decide to use a new technology that they are not familiar with. Evidently there will be a learning curve and this will impact the overall risk of the system. For example, nowadays you see many people moving their legacy app. to new platform (J2EE, .NET, etc.). That metric is hard to estimate. What&#8217;s the risk reduction when you have used a technology twice, three time, more ?. We use an heuristic approach and consider the frequency of use with the number of technology. Scaling that metric with the system that we have reviewed before is also a good approach. I don&#8217;t want to extend to much on this. But going back to your post I think the car industry is looking actively at computer backing up the driver. I have seen a prototype of alarm turning on when you get asleep while driving&#8230;There is one very popular..the GPS which actually killed a few people who took the GPS&#8217;s voice as straight order: &#8220;Turn left !&#8221; (but there was not left to make).
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
