From Rothman, an article at CSOnline discusses Moody's infosec risk rating service.
I personally dig this quote:
A non-value-add service? To quote Michael Scott, that's what she said.
The idea for such an at-a-glance rating is appealing to risk executives such as Andre Gold, head of security and risk management for ING’s U.S. Financial Services business... Last year Gold oversaw reviews of 176 new technology vendors; his team visited sites as far away as South Africa to conduct security assessments. “It’s a service that we must do, but I think it’s a non-value-add service,” he says.
photo from Dwight K. Schrute.
No comments:
Post a Comment