{"id":2073,"date":"2009-04-20T02:45:27","date_gmt":"2009-04-20T09:45:27","guid":{"rendered":"https:\/\/svapm.org\/?p=2073"},"modified":"2019-08-07T14:31:46","modified_gmt":"2019-08-07T21:31:46","slug":"greetings-salutations","status":"publish","type":"post","link":"https:\/\/svapm.org\/?p=2073","title":{"rendered":"Scrappy Information Security"},"content":{"rendered":"<p>My name is Michael Seese, CISSP, CIPP.\u00a0 Those initials after my name mean that I earn a living by worrying about security and privacy, two topics which definitely are on folks\u2019 minds\u2014and regrettably, in the headlines\u2014a lot these days.\u00a0 I used to be a programmer, working mainly in C.\u00a0 Then one day, standing in a local bookstore and surrounded on three sides by programming books, covering C++ and C-sharp and .NET and ASP, I had an epiphany: programming languages come and go.\u00a0 Guess wrong\u2014that is, specialize in the flavor-of-the-last-month\u2014and some college fresh-out will take my job, probably do it better, and for half the money.\u00a0 But the need to store data and protect data will remain and, in fact, grow.\u00a0 That realization led to my current career track.<\/p>\n<figure id=\"attachment_2077\" aria-describedby=\"caption-attachment-2077\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.flickr.com\/photos\/heraklit\/169566548\/\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2077\" src=\"https:\/\/svapm.org\/wp-content\/uploads\/security.jpg\" alt=\"Security - by dheuer via Flickr\" width=\"300\" height=\"200\" \/><\/a><figcaption id=\"caption-attachment-2077\" class=\"wp-caption-text\">Security - by dheuer via Flickr<\/figcaption><\/figure>\n<p>I point this out because it\u2019s relevant to why I\u2019m writing this week.\u00a0 Those of us who have been involved with IT for not too more than a dozen years (OK, maybe 20 years) could talk about \u201cback in the day.\u201d\u00a0 The early computers\u2014mainframes\u2014had built-in security in that they were huge (I\u2019ve never heard of a mainframe being stolen out of the trunk of someone\u2019s car), they were not networked outside of the organization (or even IN the organization!), and only super-smart geeks could run them anyway.<\/p>\n<p>Then the PC happened.<\/p>\n<p>Then the LAN card happened.<\/p>\n<p>Then Al Gore happened.<\/p>\n<p>Then the Internet happened.<\/p>\n<p>And then, e-commerce happened.<\/p>\n<p>The Information Age was fully upon us, and suddenly, every worker was a knowledge worker and every consumer an e-shopper.\u00a0 For a few glorious moments it seemed that a whole new world of possibilities was opening up for humankind.<\/p>\n<p>So back in the day, security could be an after-thought.\u00a0 Today, it has to be \u201cbaked in.\u201d\u00a0 You wouldn\u2019t buy a car that was designed and built without brakes or an engine firewall or air bags.<\/p>\n<p>That is where you, dear project management professionals, come in.\u00a0 Your opinions of security probably run the gamut from \u201cabsolute necessity\u201d to \u201cmild inconvenience\u201d to \u201c@#$@ requirement that we need to figure out how to get around.\u201d\u00a0 To be honest, sometimes I feel the same way.\u00a0 But what I need to do is convince you that it really needs to be the former, though at times I\u2019m OK with you thinking \u201cmild inconvenience.\u201d<\/p>\n<p>When conducting an information security awareness session\u2014or when addressing you\u2014I am talking to adults.\u00a0 So I cannot treat you like children.\u00a0 Rather than say, \u201cIt is what it is\u2026DEAL WITH IT,\u201d I need to explain why certain rules have to be followed.\u00a0 Training adults, I have long believed, is a lot like explaining life to a teenager.\u00a0 You could simply forbid your daughter from dating a \u201cbad boy.\u201d\u00a0 But unless you explain why (and unfortunately, even if you explain why), she will nod her head, say \u201cOK, Daddy,\u201d and then still sneak out her window at night to see her long-haired, tattooed rock-and-roll boyfriend.\u00a0 Adults can be the same way.\u00a0 You can tell them again and again that they can\u2019t use their children\u2019s names as passwords. But if you explain\u2014or better, show them\u2014 why not, they will be less inclined to simply say, \u201cYeah, yeah,\u201d and do it anyway.<\/p>\n<p>So for this week, I would like to share some of these whys, so that you can understand why the infosec guys can be so darned stubborn.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;re adults, and we like to know &#8220;why.&#8221;  I would like to share some of the whys of information security, so that you can understand why the infosec guys can be so darned stubborn.<\/p>\n","protected":false},"author":1483,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"give_campaign_id":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[2,19,20,9,1],"tags":[572,571,261,570],"class_list":["post-2073","post","type-post","status-publish","format-standard","hentry","category-leadership","category-global","category-quality","category-risk-management","category-miscellaneous","tag-infosec","tag-michael-seese","tag-scrappy","tag-scrappy-information-security"],"aioseo_notices":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/users\/1483"}],"replies":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2073"}],"version-history":[{"count":1,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2073\/revisions"}],"predecessor-version":[{"id":14211,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2073\/revisions\/14211"}],"wp:attachment":[{"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}