Live data from Hacker News

The Cyber Security Body of Knowledge

cybok.org

1–10 of 20 posts

Re: The Cyber Security Body of Knowledge

#2
Page 4 of the Scope[0] document looks particularly useful in broadly (albeit briefly) highlighting the various domains inside computer security.

Could be a nice 1 pager for highlighting some of the things I do to outsiders. Would be useful to those looking to get into this field (i.e. CS undergrad) too.

[0] https://www.cybok.org/media/downloads/CyBOKScopeV2.pdf

Re: The Cyber Security Body of Knowledge

#4
As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself.

Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very few such people with "cyber" on their resumes are hired where I work.

Re: The Cyber Security Body of Knowledge

#5

As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself. Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very fe…

Couldn’t agree more. Unfortunately however, my Masters degree was renamed from Information Assurance to Cybersecurity half-way through my program, so I have one instance of the word “cyber” on my resume, despite the eye-roll it gives me. The rest of my experience speaks for itself though.

Re: The Cyber Security Body of Knowledge

#6

As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself. Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very fe…

I think that it depends. Computer security basic and concepts maybe old but are still valid such as security models, security (engineering) principles and other security related concepts (e. g. reference monitor).

Understanding attacks can be helpful to understand vulnerabilities and wrongly implemented security principles.

Re: The Cyber Security Body of Knowledge

#7

As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself. Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very fe…

I'm not Internet famous like some of the security guys around here, but I'm good enough to get a job nearly anywhere I want. I wouldn't want to work for a place that harbors illogical grudges against benign words that over time have become used by almost everyone working in the industry. It makes me wonder what other petty things the company would be needlessly elitist and toxic about.

I've only been conducting interviews for a few years, but I haven't noticed a correlation between a lack of ability and the use of the term cyber. I don't think its on my resume (haven't had to update in a few years), but I wouldn't make assumptions about anyone that did.

Re: The Cyber Security Body of Knowledge

#8

As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself. Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very fe…

Whilst I'm not a fan of it, the term "cyber" is part of the lexicon now, and if you want to communicate to people outside the security industry about it, you'll find it easier when using that term..

It's like the old debates about the term hacker, eventually things become part of common parlance...

As to old knowledge, I'd say it very much depends. Basic principles from 20 years ago apply very much now. The specific attacks may have changed (although in some cases they're still the same) but the underlying concepts remain.

Re: The Cyber Security Body of Knowledge

#9
post #8

As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself. Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very fe…

Whilst I'm not a fan of it, the term "cyber" is part of the lexicon now, and if you want to communicate to people outside the security industry about it, you'll find it easier when using that term.. It's like the old debates about the term hacker, eventually things become part of common parlance... As to old knowledge, I'd say it very much depends. Basic principles from 20 years ago apply very much now. The specific…

> It's like the old debates about the term hacker, eventually things become part of common parlance...

Or different usages of the word "hacker" become a shibboleth for showing which of the groups (with very different agendas) you belong to.

Re: The Cyber Security Body of Knowledge

#10

As someone who has been in this game for 15 years, I have to say that by the time anyone has infosec written down and categorized it is obsolete. The CISSP, for example, bombards you with questions about thoroughly obsolete attacks. I let mine expire and allow my resume to speak for itself. Furthermore, after a couple hundred interviews over the course of my career, use of the term "cyber" is a huge red flag. Very fe…

Perhaps I misunderstand what you're saying, but it seems that I frequently hear of people's systems being compromised because they didn't, for example, install security patches and the like. Because they didn't sanitise SQL queries from untrusted sources. Because of a buffer overflow. They've been written down for years, and they're still regularly used to compromise people's systems.
Post reply on HN