5 ms·
It's a nasty sexist lie. The person had no relevant degree (as is the case for most people working in security roles, because such degrees didn't exist until v
by prvit 4y ago
It's a nasty sexist lie.
The person had no relevant degree (as is the case for most people working in security roles, because such degrees didn't exist until very recently).
The person did have a literal decades of relevant experience, working in security.
- sirsinsalot 4y agoYou're going around the threads trying to make this a gender issue. It's a valid criticism of anyone. In this case they happen to be female. That doesn't mean the criticism is motivated by gender. Your gender also doesn't excuse you from criticism.
- prvit 4y agoIt's not a valid criticism of anyone. Essentially zero people with that kind of work experience have infosec degrees. It's hard to get a formal degree on a subject which isn't taught anywhere! For example: HN loves Mudge, who also happened to just leave a CISO post, and also only holds a music degree from Berkelee.
- sirsinsalot 4y agoAnother data point, I was reading just yesterday on a HN post about fake qualifications about many male director level people without proper education. They were criticised too. I guess we all see the world as we wish.
- prvit 4y agoWe're specifically talking about a field where even a decade ago "proper education" was only offered by a couple of schools in the world. Compsci is not an infosec-related degree.
- sirsinsalot 4y agoIndependent of if the criticism is valid, it isn't gender motivated. I'll agree the criticism isn't valid. I disagree about the invalid criticism being gender biased or motivated. The subject just happens to be female. That doesn't exempt them from valid or invalid criticism. This isn't difficult really.
- thwayunion 4y ago> Compsci is not an infosec-related degree. The vast majority of the people who invented, built, and maintain all the systems infosec people are deploying had CS or CE degrees. A good CS degree provides an excellent foundation for infosec careers. In fact, at many institutions, the infosec major is very similar to the CS major. It's not everything you need, which is why a CISO should minimally also spend some time as an individual contributor in an infosec or closely adjacent group. You're moving the goalposts because your position that CISOs need no education whatsoever in the work they are leading is prime facie absurd.
- Kon-Peki 4y ago25 years ago I asked Gene Spafford why the advanced degree program was being run out of the philosophy department instead of the computer science department, and he replied that it made no sense to be part of the CS department. That's not to say that a CS graduate is or isn't the ideal candidate for the program (I think he felt that they were). But securing systems and organizations is primarily not a technical problem. You should understand that and understand the reasons why.
- thwayunion 4y agoI'm going to go out on a limb and assert that there are no Information Security departments run by Music departments.
- prvit 4y ago>In fact, at many institutions, the infosec major is very similar to the CS major. Sure, but the best security programs don't even exist in the same department as CS. At CMU Information Security is run by the College of Engineering, not by the CS department. At NYU Cybersecurity is run by Tandon school of Engineering, not by the CS department. At RIT Computing Security is run by ... the Department of Computing Security. At JHU Cybersecurity is run by Whiting School of Engineering, not by the CS department. This is because computer science and computer security are two entirely different disciplines.
- thwayunion 4y ago> They're making fun of the fact that during the data breach the CISO was someone with a music degree and no background in security. > It's a nasty sexist lie. LMAO It is literally true.
- prvit 4y agoBut it's literally not true. The person had decades of experience working security roles.
- thwayunion 4y agoIt is literally true that she had no relevant formal training. It is also true AFAIK that when she got her first role as an executive in charge of security, she had no formal training or IC experience in security. All of her "security" experience was in executive roles. Which is insane. That never happens with other types of technical leadership roles (legal, law, finance, accounting, engineering, etc.).
- prvit 4y ago>It is literally true that she had no relevant formal training. Yes, but that's also true of almost all BigCo CISOs. >It is also true AFAIK that when she got her first role as an executive in charge of security By "AFAIK" you mean that this is just what you assume without checking, right?
- thwayunion 4y ago> Yes, but that's also true of almost all BigCo CISOs. Yes, we've been over this. The article is about Equifax. I made a comment about Equifax. I've previously criticized other execs after data breaches or other major technical failures (Eg Boeing). > By "AFAIK" you mean that this is just what you assume without checking, right? No, it means I did check and she does not according to any publicly available evidence. I added the AFAIK because I cannot personally certify that her publicly available resumes are complete. It would be extremely odd to exclude relevant work experience from public profiles, so I strongly believe that she does not have relevant experience outside of exec positions (which she shouldn't have had in the first place without IC experience and/or relevant education). But I do not personally know her so I cannot personally attest that her public resumes are complete. Therefore, I added a qualifier. I can understand why this wording confuses you, though. It's a result of the fact that I have personal integrity and take words and accusations seriously.