3 ms·
> If you have a competent and fully staffed SRE Platform engineering team - you will NOT need a separate cybersecurity team. Not all cybersecurity problems are
by HotPotato787 3y ago
> If you have a competent and fully staffed SRE Platform engineering team - you will NOT need a separate cybersecurity team.
Not all cybersecurity problems are platform problems, or even technical problems. Even if you decide to gather all AppSec/InfraSec engineers inside of SRE/SysAdmin, this creates two problems:
1 - They are now separate from the main cybersecurity team, which is solving other problems and that in turn creates all sorts of issues ranging from lack of coordination to managerial ones.
2 - This creates a HUGE lack of separation of duties (or a conflict of interest). The executor of a task should never be the auditor of a task. You cannot expect the SRE team to go out of their way to keep finding flaws in their own work and exposing them to the board so they can be forced to reprioritize and fix these flaws. The SRE can and should have security built-in as much as possible, but an external team is still required.
- slt2021 3y agoSRE is really a more familiar "sysadmin" from good ole days. You know, that bearded IT guru in a basement floor, will curse and shout at you, but will keep your company running when it comes to IT. if you switch back to sysadmin model - having a single sysadmin do all the SRE and security work, divided per platform, then separate security is indeed feel like extra. You can obviously hire independent third party security auditors and do pentest, but that thing could be done once a year. Often times your financial auditors (Big 4 accounting firms) will offer IT audit and pentest in a bundle and you can get a good deal.