3 ms·
To be fair, security is an amazing amount of policy. I took and passed the CISSP, and that exam must be at least 30%, maybe 40% policy. Things like knowing how
by Bucephalus355 8y ago
To be fair, security is an amazing amount of policy. I took and passed the CISSP, and that exam must be at least 30%, maybe 40% policy. Things like knowing how does the Commerce Department’s rule of Safe Harbor apply to US companies doing business in EU. Stuff like that.
That being said, it made me way better at my job. No matter how many technical justifications I have for why we should implement X, the second I brought up a small to medium legal thing everyone would fix it immediately.
- paxy 8y agoBut how do policy changes result in a 50% increase in total expenses? They can't be hiring that many lawyers.
- xxorlak 8y agoImplementation of policies has a waterfall effect throughout the org. EG: Adding something as simple as a privilege expiration (generic example) and propagating it through the org and various teams itself will take time.
- bobdole12345 8y agoThey're hiring 2/3rd more employees to act as content moderators from the sounds of the guidance.
- cxhandley 8y agoThey're about to break the brains of 1000s of people subjecting them to aweful content. This will also have consequences. What was it "move fast and break things"!
- deleted 8y ago[deleted]
- CalRobert 8y agoEvidently it's not employees, but contractors (via Accenture, etc). Rumour around these parts is a content mod killed themselves at work a couple months ago. Wouldn't want to put that on actual employees of course!
- foobarian 8y agoYou should have seen how much harder life got at our company when we discontinued a common root password across the back office. Things that used to take 5 minutes to fix by self-service now take a ticket to the owner of a system, which can take days.
- deleted 8y ago[deleted]
- jessaustin 8y agoIf one bought into "the security story", one would expect your company after this policy change to have seen fewer random regressions due to random people rooting around in systems for which they were not responsible. Did you find that to be the case?
- rorykoehler 8y agoIt's about reducing exposure to risk more than actual occurrences. You only need to regress once for it to permanently damage your business. Just because it never happened until now doesn't mean that it won't in the future.
- jessaustin 8y agoISTM typically there would have to be more going wrong for "permanent damage"? Not that it would be surprising for a shared-root organization e.g. to have poor backup skills...
- rorykoehler 8y agoCommercial damage is often worse than technical
- Pyxl101 8y agoEven if you don't have a common root password, you can still have groups of people who are sudoers for different systems.
- zeroxfe 8y agoExample: audit all employee access to PII data. Anyone who's worked at a large company can tell you how incredibly complex and expensive this can get if your systems aren't designed for this.
- TheSpiceIsLife 8y agoThat’s upside down, me thinks. It would be difficult to incur a 50% increase in expenses without massive policy shift.
- notveryrational 8y agoReal security is almost all technical and implementation. There's a very significant danger to security that policies be some kind of front line of defense, or be implemented over sound engineering practices. In almost every work environment, I've seen the policies working directly against security: if not by contradicting it, ignoring the details where the real security decisions live, or by striking the wrong balances between prescriptiveness and generality - then by out-prioritizing security decision making. (I've worked at mostly 100,000+ person companies). It's much better to have technical security controls >80-90% of the actual security. It's just expensive and harder to teach/learn/implement. That said, there's some real security gained by policy. It comes from: - Ability to communicate expectations ("adopt technical solution X") - Ability to exercise legitimized (instanciated/codified) authority Most of the rest of the value of policy comes in as business enablement value (policies are easier to communicate to auditors than security control implementations are). Policy can also be a useful placeholder for real security in the sense it will satisfy many external parties who might otherwise reprioritize/randomize security investments.
- bdhess 8y agoPolicy is not a substitute for reasonable technical controls. But it’s also not a concern that can be wished away by saying “well we just do our security the real way, in code.” Any security control implementation enforces some conceptual policy, even if that policy isn’t documented elsewhere. In some places that’s fine; in others with more robust needs, that’s insufficient. Part of what auditors audit is that policy implementations (whether in code or in human practice) match the specification. As an example, I’m glad that browser vendors require CAs to document their policies for issuing certificates. Let’s Encrypt does a great job of making much of this process automatic, but there’s still pieces that must be done by humans, and there’s still written policies in place for all of their operations. At some point in any security process, human judgment comes into play. Striking the wrong balance between technical controls and allowing for human judgment can also lead to absurd outcomes, like this recent article/discussion[0]. [0] https://news.ycombinator.com/item?id=17350645 https://news.ycombinator.com/item?id=17350645
- 8y ago