3 ms·
Questions I have in these types of situations: * Does replacing the CISO actually make the system more secure? Presumably he had a lot of tribal knowledge buil
by ahnick 2y ago
Questions I have in these types of situations:
* Does replacing the CISO actually make the system more secure? Presumably he had a lot of tribal knowledge built-up and who is going to know the system better than him?
* As systems get more and more complex, it's likely impossible for a single individual to truly understand and prevent these types of situations 100% of the time. It seems that any application that needs to be 100% secure (if that is even possible) has to be provably secure in a strict mathematical sense, which goes beyond individual culpability.
* Does shooting the person accountable actually encourage responsible disclosure or discourage it?
- fnimick 2y agoThis one C level individual failed to do the most important part of the job, which is to build the team of people who have shared knowledge to understand and prevent these issues 100% of the time.
- jaas 2y agoNo team is going to prevent issues like this 100% of the time. That's a wildly unrealistic expectation. Wherever the bar is, it won't be 100%. That's why good leadership invests in the ability to respond well to mistakes that will inevitably be made.
- chmod775 2y agoStill. These incidents should be so rare, that when they occur, it is more likely to be leadership failure than a series of unfortunate events. This replacing the leadership is always the right response.
- HarryHirsch 2y agoDoes replacing the CISO actually make the system more secure? Counterintuitively, probably yes. Tone flows from the top down, and if you want to change the tone you need to start at the top. It's very difficult to try and build a coalition to change the system from underneath. Presumably he had a lot of tribal knowledge built-up and who is going to know the system better than him? Likely he has a lot of political influence and knowledge of the system and for lasting change all of that has to go. If it has gotten that bad it's no good and needs to be swept away.
- braiamp 2y agoBut it would also make the system more insecure since reporting failures means dismissals. At the end, DigiCert self reported the issue they were having. Without that, other operators would be blind to this flaw.