Layer 8

Security is fundamentally about people, and everything we know about people is relevant to security. -- B. Schneier

Been a long time since I’ve rock-and-rolled.

Yes, I’ve been buried in work.  I’ve been burned out.  I’ve been hung down, brung down, hung up, and ... well, you know the rest of the song.  (You DO know the Song, don’t you?)

But I stopped by to bring you this impromptu list of Interesting Things you need to know when you’re an Information Security Officer.  Enjoy.

  • Child psychology (to deal with prima donnas of all stripes).
  • Abnormal psychology (to predict which insiders will go bad).
  • Marketing.
  • Organizational training.
  • Business process engineering.
  • Which common words in the English language mean very specific things to a lawyer.  Things which will cause her to blanch when you show her a security policy or statement of work.
  • IT and financial auditing.
  • All the federal and state laws governing computers, wiretapping, breach notification, and e-commerce.
  • Economics.
  • Statistical analysis.
  • How to spell HIPAA.
  • How to troubleshoot everything from layers 1 through 7 to prove that it isn’t your firewall that’s causing a problem in production.
  • Forensics and chain-of-custody.
  • The newest naughty or infected sites, so that you can recognize their droppings on the user’s desktop.
  • Contract law.
  • Budgeting.
  • Project management.
  • Accounting.
  • What passes for risk assessment in your organization.
  • Stress management, meditation and yoga.
  • All programming languages.  Yes, even COBOL, which is still in use for an obscure, yet important application on your network somewhere.  Guaranteed.
  • Asset management.
  • How to spot snake oil encryption.
  • Public speaking.
  • QA testing.
  • RFP writing.
  • FOIA and what things not to do in email.
  • Subtle, yet effective flattery.
  • Veiled threat-making.
  • Mind-reading.

Posted by shrdlu on Thursday, March 20, 2008
(6) CommentsPermalink blogmarks Favicon del.icio.us Favicon Digg Favicon Fark Favicon Furl Favicon Google Bookmarks Favicon StumbleUpon Favicon Technorati Favicon TailRank Favicon

Comments

LonerVamp United States on 03/21  at  08:21 AM:

You need to know the intimate details of any device that runs on electricity, or batteries because you’ll be supporting it. smile

No, I don’t know that song. Gah!

Been wondering where you’ve been, nice to see a post!  =)

United States on 03/21  at  08:41 AM:

Welcome back. Sooooooo true. grin

rybolov United States on 03/21  at  03:49 PM:

Psychology to deal with the people who come to your with their personal problems because you’re “trustworthy”.
Guards, Guns, and Gates.
All the knowledge taught in a MBA program.
How to tune motion sensors and video cameras.
HR skills to hire and fire people (not just your own).
Diplomacy and political saavy.
Organizational behavior.
Industry dynamics for your company.
Criminal law not related to information security.
Whatever it is your business does:  If you make cars, the CISO just signed up to learn how to do that.

And yeah, welcome back to the land of the living.

Arthur United States on 03/21  at  04:02 PM:

@LonerVamp

A hint: Go ask Alice. I think she’ll know.

shrdlu United States on 03/21  at  04:07 PM:

@Arthur:  One pill makes you pick up the garbage in the snow, and the other makes you wanna KILL?

Arthur United States on 03/21  at  04:27 PM:

@shrdlu Just don’t be dragging out the 8x10 color glossies.

Page 1 of 1 pages

Add a comment

Name:

Email:

Location:

URL:

Smileys

Remember my personal information

Notify me of follow-up comments?

Submit the word you see below: