3 ms·
Defensive infosec is mostly "liability and risk reduction." Why is "risk reduction" seen as a bad thing?
by g-clef 9y ago
Defensive infosec is mostly "liability and risk reduction." Why is "risk reduction" seen as a bad thing?
- kodablah 9y agoIt isn't always, but when it is, it's because the costs outweigh the benefits. Usually this is in the form of lack of employee flexibility to do the best for the company (i.e. red tape and hoops become an impediment). However, in this case the cost is employee privacy. You might argue that they have none and spying on all traffic is reasonable, but many times these policies encourage employees to use workarounds that are even more dangerous just so they can have a modicum of privacy (e.g. alternative and less-vetted software packages, non-company hardware, etc).
- g-clef 9y agoHaving worked defensive infosec for almost 2 decades, the privacy-invasion-leading-to-insecure-workarounds is not my experience. (US-based, I'll grant. I'm sure my experience would be different in Germany, for example.) As long as the inspection was transparent (which it was until the TLS 1.3 discussion started), employees mostly didn't know they were being monitored, and they didn't care even when they learned they were. Folks who got caught downloading porn or running their side-business over the work network were surprised that we were looking for that stuff, but no one felt like their privacy had been violated.