Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 20, 2007

Infosec: Red Headed Step Child

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

We in computer security are the red-headed step children of IT. The result of our job is a zero sum gain. If we do our job right, nothing happens. Costs don’t go down, sales don’t go up. It’s hard to justify our benefit to the bottom line unless you’ve had a breach and realize the true costs of bad security. Just ask retailer, TJ Maxx if they understand the value of Infosec. They had a very public breach last year that caused the release of some 45 million customer credit cards. The costs have soared to over 100 million dollars and that doesn’t include the likely payout of a huge class action law suit. The company will be lucky to survive this debacle. Of course, costs are averaged over a whole industry just like insurance so it’s unlikely (but not improbable) that you would have endure these kinds of costs. Good Infosec is like good insurance or border security. We stand eternal guard against the unlikely but unthinkable.

Of course, as my partner noted in the previous blog, in regulated industries like banking, Infosec is a fact of life. It’s as central to your charter as keeping enough in reserves to cover your deposits. And most larger companies and e-business concerns take e-security seriously.

But mostly, like Rodney Dangerfield, we get no respect.

We are the rule makers and no one likes the rule makers. Our jobs is to be the jerk, be the SOB who won’t let you do your job the way you want to do it. And in this day and age, you can’t tell anyone not to do anything a certain way, even if its for their own good. Everyone wants to do their own thing.

Us Infosec types hark back to an age when the workplace had real rules. You dressed a certain way, you did your work a certain way, and individuality was not a trait that got you ahead. Of course we have lots of rules these days, but they are mostly related to stuff that just doesn’t matter. Like don’t make dirty jokes (least not in mixed company), don’t hoard your vacation (god forbid someone wants to save up for a month long vacation by not taking any for a year or so), don’t smoke and so forth. The workplace has become long on useless rules, short on meaningful rules which breeds disrespect of any rules for any reason. Women and men wear whatever they pull out of their dirty clothes hamper (or underwear drawer), slap on some shower shoes loosely disguised as sandals and come to work and surf Victoria’s Secret (perhaps for more work attire) or “Guns and Ammo” or whatever pops into their head that day.

We in Infosec have some rules for you. One of the few benefits of being an Infosec guy is that you get to enforce the rules all the way across the spectrum, no matter what their rank or title. We have to go after the boss just as hard as that rank and file guy. We have rules, and you best follow them. Or your application won’t run, your mail wont go through, or if you are peeking at the wrong stuff, you could end up in the unemployment line. So if you don’t want to follow the rules, just stay home. You can dress any way you want there.

These days, many security companies try to be the kinder, gentler Infosec guys in order to market to the rank and file, the unwashed masses as to why we should exist. . I say lets unabashedly do our job. I say how about just follow the rules. We don’t particularly like users and let’s just admit it. They mess up our nice neat firewalls with exceptions and rules and they figure out ways to get around our restrictions. We aren’t here to be your friend or your mother, we are here to protect the company and its info-assets. It’s a non-stop, thankless job but somebody has to do it or there is the chance that you won’t have a job tomorrow (i.e. TJ Maxx employees). Of course without users, we’d be out of a job.. so, on second thoughts, keep it up guys! Good work!

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.





Search Fearless Security
 
Fearless Security
OCTOBER 2008
    1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  
or

 Recently in Fearless Security
Hacking Palin...
Make a Comment
Hurricane Preparedness for IT
Make a Comment
Defcon Buzzword Bingo

Last Comment
I looked at the defcon website and noticed all the contest and events along the top of the main page...
(3 Comments)
A Black Hat Glass Half Full

Last Comment
So, which is the one of their best security conference?...
(1 Comments)
BlackHat and the DNS Non-Event
Make a Comment

More blogs about technology,
software, and Windows.

ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Microsoft Exchange & Windows Connections event returns to Las Vegas Nov 10 - 13
Connections returns to Las Vegas for this exciting event where each attendee will receive SQL Server 2008 standard with 1 CAL. Co-located with Microsoft ASP.NET, SQL Server, and SharePoint Connections with over 250 in-depth sessions.

Free Online Event! Virtualization:Get the Facts!
Register now and attend this free, live in-depth online conference on November 13 and 20, 2008, produced by Windows IT Pro. All registrants are eligible to receive a complimentary one-year digital subscription to Windows IT Pro (a $49.95 value)!

Check Out Hyper-V Video on ITTV
Watch Karen Forster's interview on Hyper-V's performance on ITTV.net.

Ease Your Scripting Pains with the Flexibility of PowerShell!
Join MVP Paul Robichaux on December 11, 2008 at 11:00 AM EDT as he equips you with PowerShell basics in 3 introductory lessons, each followed by a live Q&A session—all on your own computer!

PASS Community Summit 2008 in Seattle on Nov 18-21
The don’t-miss event for Microsoft SQL Server Professionals. Register now and you’ll enjoy top-notch Microsoft and Community speakers and more.



Speed Up Your PC!
Try Diskeeper 2008 with InvisiTasking Free Now!

Get Protected -- Data Protection Manager 2007
Protect your virtualized environment with Data Protection Manager

Agent-less Remote Backup Service, Free 30 Day Trial
Award winning remote backup service at a competitive price with no min GB/month. Sign up Now!

ScriptLogic Cartoon Caption Contest
Submit your caption and you will be entered to win $198.42

List Your Products in Our Technology Resource Directory
Don't miss the chance to post your free listing in this comprehensive directory for IT and developer professionals, powered by Windows IT Pro. But hurry! Deadline ends Oct. 9.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing