3 ms·
This is a very naive view of information security. The most sophisticated approaches to modern security - either in technical app/net sec or in risk management
by throwawaymath 8y ago
This is a very naive view of information security. The most sophisticated approaches to modern security - either in technical app/net sec or in risk management - begin from the assumption that vulnerabilities exist and will be exploited.
Every security team should be proactively trying to eliminate security vulnerabilities. But they will happen nonetheless, and the mark of truly secure organizations is in the way they respond to such vulnerabilities.
At the CISO level this becomes even more important: a CISO is not only responsible for setting the organizational mandates for security. They are also responsible for being the public face which responds to notable security events.
- m0zg 8y agoWell, neither Yahoo's nor FB's security teams have eliminated the gaping security holes in question, from which I conclude that maybe he just isn't as good as his "public face" would imply.