Create an Account
username: password:
 
  MemeStreams Logo

TaoSecurity: "Untrained" or Uncertified IT Workers Are Not the Primary Security Problem

search

Decius
Picture of Decius
Decius's Pics
My Blog
My Profile
My Audience
My Sources
Send Me a Message

sponsored links

Decius's topics
Arts
  Literature
   Sci-Fi/Fantasy Literature
  Movies
   Sci-Fi/Fantasy Films
  Music
   Electronic Music
Business
  Finance & Accounting
  Tech Industry
  Telecom Industry
  Management
  Markets & Investing
Games
Health and Wellness
Home and Garden
  Parenting
Miscellaneous
  Humor
  MemeStreams
Current Events
  War on Terrorism
Recreation
  Cars and Trucks
  Travel
Local Information
  United States
   SF Bay Area
    SF Bay Area News
Science
  Biology
  History
  Math
  Nano Tech
  Physics
Society
  Economics
  Politics and Law
   Civil Liberties
    Internet Civil Liberties
    Surveillance
   Intellectual Property
  Media
   Blogging
Sports
Technology
  Computer Security
  Macintosh
  Spam
  High Tech Developments

support us

Get MemeStreams Stuff!


 
TaoSecurity: "Untrained" or Uncertified IT Workers Are Not the Primary Security Problem
Topic: Computer Security 11:55 am EDT, Jun 11, 2010

One of my biggest gripes about the upcoming cybersecurity legislation is the threat of mandatory certification for security professionals.

I didn't get a chance to thank Richard Bejtlich for his kind comments regarding my Blackhat talk, so let me take the time now to thank him for taking a stand on this issue:

There's a widespread myth damaging digital security policy making. As with most security myths it certainly seems "true," until you spend some time outside the policy making world and think at the level where real IT gets done.

The myth is this: "If we just had a better trained and more professional IT corps, digital security would improve."

This myth is the core of the story White House Commission Debates Certification Requirements For Cybersecurity Pros.

My opinion? This is a jobs program for security training and certification companies.

Here's my counter-proposal that will be cheaper, more effective, and still provide a gravy train for the trainers and certifiers:

Train Federal non-IT managers first.

If management truly understood the risks in their environment, they would be reallocating existing budgets to train their workforce to better defend their agencies.

TaoSecurity: "Untrained" or Uncertified IT Workers Are Not the Primary Security Problem



 
 
Powered By Industrial Memetics
RSS2.0