Tales of Ordinary Madness

Chris’ Tales of Ordinary Madness

Archive for October, 2011

Stupid Information Security people

with 3 comments

duh

I hope that headline got your attention. That was my goal. It’s offensive when someone generalizes about the overall intelligence and thoughtfulness of an entire group of people. And yet, that’s the habit we as an industry seem to have fallen in to. In IT and in InfoSec, over and over again I hear “Stupid users”, “those idiot users”, “my users are such dumb shits”. It’s almost a mantra; it’s uttered that frequently.

My focus here is in the security realm because that’s where I am and what I do. In the security community, I hear the sentiment echoed over and over again as well. Dumb users who repeatedly “click on shit” that ends up compromising my security. I’d like to turn that around a bit. Any time one of my users “click on shit”, I’d like to suggest that it is I who have failed and not them. Myself and my team have failed to properly educate them, I have failed to teach them how to identify the latest phishing scam, we have failed to teach them to type the URL themselves rather than blindly clicking on links. We have let the company down, not those “dumb users”. I feel very strongly that a big part of my job should be end user education. As tired as military analogies maybe, they are our front line, they are our border guards. Without their participation and involvement in securing our environment, we can’t ever hope to be successful.

So please stop looking down at those “dumb users” and make them a part of your security team. Educate them and make sure they understand that they play a vital part in securing the enterprise. In fact, as a whole, I could argue that they play a much more important role than you do, so please act like it.

Also, please consider bringing your expertise to the newly launched Security Awareness Training Framework (SATF). We are working to develop a framework (similar to what is being done with Penetration Testing PTES) that will help security programs and practitioners develop a complete and comprehensive security awareness program. This isn’t a small task but we are a small group of folks working on this in our free time and any extra set of hands would be appreciated.

P.S. I don’t think information security folks are dumb, in fact, I’m often awed and intimidated by the intelligence of some of my peers.

Written by Chris

October 17th, 2011 at 2:51 pm

Posted in Uncategorized

Pittsburgh area loses another law enforcement officer

without comments

http://www.postgazette.com/pg/11286/1181855-100.stm

This is becoming a disturbing trend in Pittsburgh. My thoughts today are with the family, friends and fellow officers of Derek Kotecki.

My dad had a variant of this poem framed when I was growing up. I always found it very moving and it is appropriate for today.

A police officer stood at the pearly gate,
His face was scarred and old.
He stood before the man of fate
For admission to the fold.
“What have you done” St Peter asked,
“To gain admission here?”
‘I’ve been a police officer sir,’ he said,
‘For many and many a year.’
The pearly gates swung open wide
As Peter touched the bell.
‘Inside,’ he said, ‘and choose your harp.
You’ve had your share of hell.’

Written by Chris

October 13th, 2011 at 8:13 am