4 ms·
It's great if the higher up executives / managers starts valuing security, and are more open to the idea of reallocating more company resources (employee time)
by automatwon 10y ago
It's great if the higher up executives / managers starts valuing security, and are more open to the idea of reallocating more company resources (employee time) accordingly.
How will this pragmatically trickle down to middle managers and their subordinates? With politics and personal incentive that are potentially unaligned with the company's long term interests (not having a data breach), will more resources actually be spent on security?
The return on investment of information security is not obvious / tangible, especially on a quarterly basis. Data breaches are "black swan" events, rarely occurring but with disproportionate consequences when they do occur. It's harder to quantitatively track progress, or lack thereof, of investment into security.
People can (over) claim the amount of time reallocated to security. These claims would be hard to falsify. Teams who are behind on other deadlines can blame time being reallocated to information security. Managers can use the purported reallocated time to spend on feature work, or whatever it is that makes them look objectively better for promotion.
I admit I'm being a bit cynical. I think company culture would help mitigate these issues. Executives valuing information security, even if it's just words rather than policy, nurtures such a culture.
- kevinstubbs 10y agoFrom the top down, executives need to communicate that it is a company priority. Even better if they can make it a cultural thing, instead of an afterthought. A lot of the time, engineers just don't know best security practices or in the case of web development, common exploits[0]. For middle management and below, if upper management doesn't care about security, despite the "look at Yahoo" argument, then you'll find no leverage there for security funding. If they care at all, then managers and individual contributors can argue for security to stand out and accelerate their career. Yahoo's security troubles brighten the spotlight on the need for security funding at companies for training, audits, and setting aside time to do retroactive security work. It's not a silver bullet, but it helps. [0] OWASP has a lot of great web security resources. Here is their top 10 list from 2013, https://www.owasp.org/index.php/OWASP_Top_Ten_Cheat_Sheet https://www.owasp.org/index.php/OWASP_Top_Ten_Cheat_Sheet