My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…
I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…
Ceremonial security and cargo cults
41–49 of 49 posts
Re: Ceremonial security and cargo cults
#42My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…
I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…
Re: Ceremonial security and cargo cults
#43Earlier quoted context omitted.
I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…
"I used to be a lawyer but now work in IT", "I'm reporting and escalating your non cooperativeness right now"
Give me all of the hungry musicians that you can find though, they're great systems-thinkers.
Re: Ceremonial security and cargo cults
#44I’ve found it immensely frustrating in numerous roles when discussing security, audit and compliance requests that the requesters can seldom actually explain their reasoning. I want a clear statement of risk and why their proposed compensating control actually mitigates it. Far too often the answers are just “it’s securerer” or “it’s the way we do it”, and actually proposing something that genuinely mitigates the und…
To put it another way, using a risk-mitigation approach instead of compliance only works when you have honest, earnest, and full good faith investment in the process. In practice, this is incredibly rare. We all know, are, or have been engineers who cannot imagine a system they wrote running without them having the ability to SSH in and sudo at will without having to justify anything.
This is where compliance comes in. It sets standards and forces the issue. Even bad faith, low-effort implementations wind up having to meet a whole series of very clear - if occasionally box-tick-y - standards.
Re: Ceremonial security and cargo cults
#45Earlier quoted context omitted.
No offense, but I think you're exactly wrong. People need to trust the science, so to speak, and leave the thinking to domain experts who can dictate the best course of action for everyone. On their own, too many people are prone to following misinformation, and can't even be trusted to read both sides of any given argument critically. If the last few years hasn't taught us this lesson, what has it taught us?
Should we have trusted the experts on satanic ritual abuse in the 80s and 90s? I have many gripes with this attitude; experts can be wrong and even entire fields can be wrong. The satanic ritual abuse is a particularly egregious example with many "experts" mouthing off complete nonsense, but also see e.g. the replication crisis. And which expert do you believe? There are many expert. "You've got to ask the right expe…
These stories happen all over the place, and still repeat themselves when it comes to how disabled poeple are treated in institutions today.
Still, some conservatives are still willing to wink anything through a self-proclaimed expert utters to the masses.
Re: Ceremonial security and cargo cults
#46The security cameras.
The door logs.
The DNS and netflow logs.
Ok, not sure about 10,000 screenshots showing nobody has admin access...
Re: Ceremonial security and cargo cults
#47My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…
> Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. There is one company I know of that added a two step login to their azure active directory where logins expire every twenty four hours. It made no sense to me why they did things this way. As far a…
"... cookie validity is 30 days. They only expire when the user logs out, or after 30 days."
Re: Ceremonial security and cargo cults
#48Earlier quoted context omitted.
The “proof via a series of tedious screenshots” method of audit is absolutely infuriating. Please bring on the 10x auditors…
When you don't know what you're doing, dazzle them with bullshit. Best part of the story above is that in our system there are no human users that can access a live system. And proof of that is insufficient because the IT person isn't familiar with the practice.
100% because most people don't know what makes good security so it is easy to get them to mistake volume with quality.
Re: Ceremonial security and cargo cults
#49My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…
I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…