3 ms·
As a security person trying to work with marketing and data engineering teams, I've often found them very resistant to learning how to secure things. They gener
by Kalium 2y ago
As a security person trying to work with marketing and data engineering teams, I've often found them very resistant to learning how to secure things. They generally want to use the tools they know, in the way they know, to do the tasks they understand, on a timeline they find convenient.
Anything that tries to get them to understand the risks they are taking or the sensitivity of the data, much less de-risk their workflows, is treated as an obstacle to be routed around. Often, the best I can hope for is a token effort at negotiation where their goal will be to avoid any and all changes on their part. After which I will have to monitor them carefully, because from experience the odds of them backsliding within a week are uncomfortably high.
Nothing about this is conducive to producing a healthy environment. When people's idea of "easy" is they can download the company's most sensitive data to their laptop to load into Jupyter, any amount of security controls will come as an imposition.
- bluedemon 2y agoA question for you and anyone else in security: Given that many data engineers have a data science, data analytics, BI, or software engineering background, I'm curious if you've noticed any trends in their approach to data security?
- Kalium 2y agoYes. Generally it can be summarized as "What data security?". Snark aside, there's usually a reflexive assumption that more data is always better and that anything that gets in the way of more data is bad. Anything that limits how data is analyzed is bad. Anything that limits or restricts their choice of tooling or where they use it is rejected. Data scientists and engineers are people who are, often, working with a company's crown jewels. They are trusted with data representing the private lives of hundreds of millions of people assembled in a data warehouse. I want them to have a care. To treat this with due gravitas. All too often, all they seem to see is a neat data set to feed into R on their Macbook.
- wodenokoto 2y agoLog in to your vpn, then log in to a website to download a token. Then use said token to log on to a virtual desktop. From here you can open a browser and log in to powerBI, which has access to data in the data warehouse. Yes, such workflows are something to be routed around.
- Kalium 2y agoYou're absolutely right. The token is clunky. The rest - a VPN to a virtual desktop - is entirely reasonable.
- wodenokoto 2y agoFor logging in to an online service?
- Kalium 2y agoFor delivering strict network access controls, a clear audit trail at multiple points, and (at a guess) the usage of very temporary credentials to actually log in, yes. Especially if the same infrastructure is used for other, less SaaS-centric data handling tasks or users are in places that like to mandate access to geo-local data (India, China, etc.). Security measures in operational workflows are only a little bit about what the end user - you - sees. Generally they're really about delivering something less obviously visible to the user but very valuable to the business, investors, and regulators.