Events and Causal Factors Analysis

11 PM June 23, 2003

Charles Miller, in his recent post on Penetration Testing, wrote:

A successful penetration indicates something more than a particular security flaw. It indicates some systemic flaw in network security policies or practices.

and:

If the penetration is successful, it is to… practices and procedures that management should return, to examine how they could be better implemented, or more clearly communicated to employees.

Events and Causal Factors Analysis is a technique for analysing and communicating the systemic and indirect causes of incidents. It would be useful for examining faults in practices and procedures after a ‘successful penetration.’

By alang | # | Comments (1)
(Posted to Software Development)

Comments

At 10:05, 17 May 2005 John Kingston wrote:

If you are interested in Events and Causal Factors Analysis you might visit www.nri.eu.com and download (no charge) the manual on ECFA+. This is an updated version of the ECFA method.

(#)

Add Comment




(Not displayed)






(Leave blank line between paragraphs. URLs converted to links. HTML stripped. Indented source code will be formatted with <pre> tags.)




© 2003-2006 Alan Green