4 ms·
It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're el
by a2tech 5y ago
It's IT via checklist. I can't imagine a more depressing way to go through my life. Talking to the cybersecurity people I know they all frame it like they're elite warriors who are locked in a titanic struggle with cunning adversaries. My take is...you followup on tickets generated by third party tools by filling out web forms. Yes you're getting 'probed' by Russia and China all the time but thats from botnets looking for ancient vulnerabilities. You're not single handedly keeping the barbarians back from the gates. You're paper pushers.
- Hujiuu 5y agoIt might be something similar as it is in software development. At the end of the day it is a job. But when you part of the 1% of the good people you have your team and more leaway and potentially get called for the more critical and more interesting things.
- ethbr0 5y agoA roommate studying for aerospace engineering described that field as "Everyone gets in because they want to work at Skunkworks and design the SR-71. In reality, 95% of graduates will spend the next 40 years optimizing the efficiency of a winglet on a 747." Security feels similar. The edge of the spear is fascinating, exciting, challenging work. Unfortunately, no one needs that work. What companies actually need is mind-bogglingly slow, comprehensive, steady progress and improvement of their postures.
- NikolaeVarius 5y agoIts so true, was very depressing when working at my first aero job
- rz2k 5y agoOptimizing the wingtip on a 747 actually sounds interesting, and it's the sort of thing that could meaningfully affect the world. It might even prevent more wars than the SR-71 program in terms of lessening ecological and environmental pressures. A much worse career would be convincing regulators that new aircraft like the 737 MAX don't need any additional training. Maintaining lists of open exploits, and keeping them secret from vulnerable parties is that kind of job, where you're making the world less safe in a perversion of your ostensible goals.
- jhloa2 5y agoWould that task keep you interested for many years? A lot of the people I know in Aerospace end up working on a single component of a larger system for so long that they lose interest and burn out. It's a very high paying job for mostly very boring work. There are always exceptions though.
- commandlinefan 5y ago> Optimizing the wingtip on a 747 actually sounds interesting That was my first thought as a software dev - I'd love to be able to spend time _optimizing_ something rather than breaking my "stories" down to one-to-two hour "tasks" and justifying my "estimates" every morning.
- Retric 5y agoAsk anyone in Aviation, checklists matter. Cybersecurity is often drudgery, but avoiding excitement is the entire point.
- specialist 5y agoCurrently, IT checklists are security theater. Reducing liability vs improving security. How many orgs are transitioning to zero knowledge networks, encrypting all data at rest?
- Retric 5y ago> encrypting all data at rest That’s a common checklist item. Implementing it is of course more work than just checking the box, but ensuring it’s actually done means it’s added to a lot of different checklists.
- syntaxstic 5y agocheckmate
- specialist 5y agoAt the field and record level? Sufficient to guarantee privacy? Never store PII as cleartext, akin to proper password storage. Translucent Databases https://www.amazon.com/gp/product/1441421343 https://www.amazon.com/gp/product/1441421343 Encrypting databases, file systems, and backups remain necessary, but insufficient.
- netflixandkill 5y agoEncrypting data at rest at least is getting better if only because more systems do it by default as time goes on.
- nytesky 5y agohttp://atulgawande.com/book/the-checklist-manifesto/ http://atulgawande.com/book/the-checklist-manifesto/ Yes, Checklist in aviation and aerospace are crucial, but at the same time, you have to avoid checklist for checklist sake. But they also do a lot of failure response testing, simulations where you walk through a failed checklist or incidient and how you would response. Cypersecurity does pen testing and phishing attempts, but how about dry runs where you act as if you are compromised and everyone runs a "fire drill" scenario?
- insickness 5y agoIf you're looking for a career with literally no bureaucratic overhead--no checklists, no tickets, no paper pushing, then IT is not the field for you. Every IT field has bureaucratic overhead. Yes, beginners rely on checklists more than experienced people do, but that's the same for any field.
- ludamad 5y agoDon't be so hard on checklists :) the bigger problem is applying ill conceived checklists no?
- mistrial9 5y agoI suspect the underlying psychological tension is between "learn-design-create" versus "obey-follow playbooks-be reliable" People like me took decades to stop fighting the latter. Security is "for those that pay" in most cases, which also can set up some social tensions for those who consider larger social issues. make sense?
- PeterisP 5y agoOn one hand, the security checklists are laughably insufficient, you can tick all the boxes and still have systems with as many holes as Swiss cheese. On the other hand, so many real breaches have happened because very basic things weren't done, and a basic checklist would have shown that they aren't done. But of course, that checklist would not cause the organization to provide the resources and motivation to actually fix the issues. The big problem with checklists is that organizations inherently don't really want to invest to fix these problems, they have other priorities, and if someone else forces a checklist on them, then they often will explicitly prioritize ticking off the boxes (with any caveats they can negotiate or hide) at the expense of actual security.
- deleted 5y ago[deleted]