Firewall Wizards mailing list archives

Re: InfoSec Consultant Liability Question


From: "Marcus J. Ranum" <mjr () nfr net>
Date: Mon, 01 Nov 1999 09:28:53 -0500

You shouldn't focus your efforts on insurance, but on stressing to your
clients the risk element of security. How much money do they want to spend
on lowering the risk ?

I agree. The first thing in _any_ consulting engagement is setting the
customer's expectations correctly.  If you think the customers'
expectations are unrealistic then you'd better expect trouble, walk
away from the project, or hope you get lucky.

mjr.
--
Marcus J. Ranum, CEO, Network Flight Recorder, Inc.
work - http://www.nfr.net
home - http://www.clark.net/pub/mjr



Current thread: