4 ms·
I feel you. These "cyber security" people's main qualification appears to be scoring 70% on a multiple choice test. I've seen people with no practical experie
by bithive123 2y ago
I feel you. These "cyber security" people's main qualification appears to be scoring 70% on a multiple choice test. I've seen people with no practical experience building things be paid more than 25+ year veterans (who, by the way, might know a thing or two about security).
The CIO and CISO don't understand that certifications only tell you someone is minimally qualified (at best). They are afraid of what they don't know (which is everything) and looking for something to conform to, some external authority on which to base their cargo cult. But they don't want to learn anything more complicated than a buzzword, so their first and last interview question for a security candidate is "what is the CIA triad?"
The old timers don't seem particularly anxious about security (because they understand where and how the rubber meets the road), which is misinterpreted as complacency.
So the security team will insist on not learning anything about the environment at their new job (separation of duties!) but will want to install footguns on every server, and generate reams of automated scanner output that is 98% useless. Budgets get eaten up because we have to buy products from the magic quadrant, because they need to be easy enough for an under qualified person to use (I've heard this). Sometimes it feels like never-ending stream of XY problems and Chesterton's fences, but I guess that's just another day in IT.