5 ms·
It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, th
by Sebguer 5y ago
It's incentivized top-to-bottom. Every audit is structured around checking boxes, absolutely zero interest in actual security. Just state you have processes, that they meet the loosely written (or in some cases bizarrely specific) spec, and be able to provide some writing that explain them at least at a surface level.
This is the case for just about every framework, and even though these systems are just for window dressing, the auditors are mostly incompetent. A review a few years ago showed that 20-50% (depending on which of the Big 4 you've decided to hire) of audits were done incorrectly.
- qzx_pierri 5y agoI recently quit my job in Information Security. We used the NIST 800-53 framework. 99% of people following security frameworks just blindly check in boxes during audits or control assessments. A security control/requirement can’t be met? No problem! Just create another piece of paperwork accepting the risk and get it signed off by the system owner (who has the most incentive to not inconvenience their project or department due to an outstanding security requirement). The things I saw that were labeled as “acceptable risk” would drive me crazy. Maybe the government hires incompetent security practitioners? Do all organizations have this type of behavior behind the scenes?
- Sebguer 5y agoThe entire system is about abstracting away liability, not keeping things secure. Every framework is like this. The fact that companies are paying auditors to review their own work creates a completely upside down incentive model, and turns it into effectively a rubber stamp. You have to do things horrifically wrong for an auditor to care, and it's not like they're actually going to fail you, they'll just tell you to fix it and give you a generous deadline (or, for frameworks that allow it, do what you described and have it signed off as a known risk).
- agar 5y agoThe flipside: I've recently been working with a company that was audited and called out for allowing too many security policy exceptions. As a result, unless you can satisfy every one of their requirements, regardless of mitigating controls, you cannot get installed. Even if you're a security product whose ultimate use case is discovering in-progress exploits. I'm not sure if that's an example of the system working or being broken. But overall, Information Security is a complicated problem.
- ainiriand 5y agoI was working for one of the Big 4 in risk assessment and this is 100% how it works.
- _wldu 5y agoThey want us to be compliant, not secure: https://www.go350.com/posts/they-want-us-to-be-compliant-not-secure/ https://www.go350.com/posts/they-want-us-to-be-compliant-not...