Join 📚 Favorites And Reflection Questions

A batch of the best highlights from what Todd's read, .

The fundamental purpose of God’s prophets, then, is to make peace by calling us to the repentance that leads to reconciliation and by simultaneously advocating for the material and social conditions that make peace possible. And I think that the reason prophets run up against civil authorities so consistently is precisely because the work of creating peace requires confrontation with the forces that undermine peace through exploitation and violence. Peace is not the same thing as quiet.

With Love We Shall Force Our Brothers: Prophetic Peacemaking With James Baldwin by Anthony Barr

plough.com

What the CISO needs is a “Return on Control” calculation. That is the monetized value of the reduction in expected losses divided by the cost of the control.

How to Measure Anything in Cybersecurity Risk

Douglas W. Hubbard, Richard Seiersen, Daniel E. Geer, and Stuart McClure

To briefly recap, here’s a few of the things that we take away from this journey: If you can do one thing to manage a large product security portfolio, do bulletproof authentication; preferably as a property of the architecture Security teams and central engineering teams can and should have a collaborative, mutually supportive partnership “Productizing” a capability (eg: clearly articulated; defined value proposition; branded; measured), even for internal tools, is useful to drive adoption and find further value A specific product makes the “paved road” clearer; a boolean “uses/doesn’t use” is strongly preferable to various options with subtle caveats Hitch the security wagon to developer productivity Harvesting intent is powerful; it lets many teams add value

Securing Netflix Studios at Scale Netflix TechBlog | Netflix TechBlog

Netflix Technology Blog

...catch up on these, and many more highlights