Live data from Hacker News

Security Is a Useless Controls Problem

securityis.substack.com

81–83 of 83 posts

Re: Security Is a Useless Controls Problem

#81
post #59
post #12

The vast majority of the security "industry" is about useless compliance, rather than actual security. The chimps have put their fears into large enterprise compliance documents. This teaches the junior security people at enterprise companies that these useless fears are necessary, and they pass them along to their friends. Why? Not just because of chimps and fear, but also $$. There is a ton of money to be made off…

Compliance is useful, just not for security. * You get a cool industry certification that you can put on your website to justify the vague "we take your security seriously" platitudes we spew. * It lets you stop putting money and effort into security once you've renewed your certs this year. * You don't need to hire a dedicated security person, any sysadmin can check boxes. * You can say you followed industry best pr…

Your first sentence isn't necessarily true

There is compliance everywhere and compliance is often complying with larger industry "requirements" or considered best practice controls.

If you start a business from scratch, I don't know any company that has developed their own controls library from scratch without complying with some sort of framework or baseline controls set.

The frameworks and control sets that you often comply exist and are there for a reason, but your mileage may vary if you choose to use them.

Re: Security Is a Useless Controls Problem

#82
post #75

Earlier quoted context omitted.

My understanding is that Essential Eight doesn't require password rotation

If so then I'll be doubly frustrated - I've been assured by our domain experts that this is a requirement of the model. Did it used to be and was since retracted? I suppose it may be a local or state-based 'implementation augmentation'. I've trawled just now through the signals directorate site and can find plenty of references to passwords, but nothing specifically covering this.

It may have been as password rotation was a requirement thrown around, but to my knowledge it's not come up in assessments for a long time.

Re: Security Is a Useless Controls Problem

#83

I just read the book The Phoenix Project. It's over a decade old so some of the principles are obvious/quaint at this point, or perhaps not quite as applicable. That said, one of the things that caught me off guard is the dressing down of the head of security by a member of the board. More or less, they were told what they did was clog the flow of useful work. The message conveyed is similar to this post.

Security is always an economic activity too. The crash engrs at Ford could demand 30 mph speed governers, quarter inch steel plates, 5 point harnesses, and helmets, but people need a car that costs less than $200k and gets more than 2 miles per gallon.

Sometimes security requirements _are_ too onerous.

Post reply on HN