5 ms·
This is an interesting notion, but I wonder if there would really be support for such laws. In Canada, you can't even call yourself an "Engineer" if you aren't
by mabbo 3y ago
This is an interesting notion, but I wonder if there would really be support for such laws.
In Canada, you can't even call yourself an "Engineer" if you aren't an accredited P.Eng license holder. And a P.Eng who signs off on safety related designs that aren't safe (or signs of pretending to be a P.Eng) can actually go to jail. And that's something I fully support.
But would people support similar laws for information security? I would, but would enough people that the government would pass such rules? Hard to say.
- lifeisstillgood 3y agoIt took, depending on when you say who the first "engineer" was, several hundred years (let's go from Christopher Wren to the 1828 charter of institute of civil engineers). So we have time. But we could easily establish minimum best oroactises for computer security, data security, PII management etc (we more or less have with say SOC2). This is why the people that asked "when was your last penTest" got it wrong. They should have said "show me your SOC2 certificate". Then whatever lies the salesman says are obviated by going and asking the accreditation agency. All we need to do is migrate the SOC2 from a paid for box ticking exercise into something valuable
- rplst8 3y agoSome states, like Oregon I believe, have similar prohibitions about the word "engineer" being one's job title. Others only prohibit signing off as a PE unless certified. Most life critical systems, such as medical devices, bridges, and buildings, require a PE to sign off in the states. Removing the "engineer" from a title or position that doesn't require a PE is not likely to happen, and is really just semantics. The bigger issue I see, especially with DoD IT systems, is that the federal government career field that manages those requires NO education.