Analytics
9/20/2013
05:49 PM
Tim Wilson
Tim Wilson
Commentary
50%
50%

(ISC)2 Congress Addresses Security's People Problems

Annual (ISC)2 conference puts technology aside to focus on the human side of security

There are many conferences and get-togethers around cybersecurity every year, but only a few would be considered "mandatory" by the whole community of security professionals. The RSA Conference, held each year in San Francisco, offers the industry's biggest exhibit floor and a chance to see security products in action. Black Hat USA, held annually in Las Vegas, is where the smartest and best security researchers come to reveal vulnerabilities and share knowledge on potential threats.

While these events offer a depth of technological insight unmatched in IT security, though, they don't necessarily focus on the "people" issues faced every day by the average security professional. That's why I'll be in Chicago next week for the third annual (ISC)2 Security Congress, the yearly meeting of the world's biggest cybersecurity professionals' organization.

(ISC)2's Congress -- held concurrently with ASIS, the granddaddy of physical security conferences -- doesn't have an overriding technological "theme" because it isn't focused on technology. Its focus is discussing the day-to-day, nonsexy issues that all security professionals grapple with, such as staffing, hiring, management, and administration. Where other events might have more of a "show" of leading-edge technology or new threats, (ISC)2 is more like a water-cooler conversation among colleagues faced with similar security problems and issues.

Meetings of security professional organizations, such as (ISC)2, ISSA, and ISACA, represent the "everyman" infosec pro, who may not always be up on the most current products or attacks because he or she is fighting the everyday fires of the enterprise. These are people who work in the trenches of security and are limited by time, budgets, and short staffing. They spend a frustrating amount of time in meetings, arguing with top executives or end users who don't understand the dangers their systems face every day. Their job is not to be on the leading edge, but to get their data secure as best they can with what they've got.

This year, many of (ISC)2's sessions will focus on how to do more with less, how to train staffers and end users to improve enterprise defenses, and how to make tough decisions about security in a rapidly changing environment where the needs of the business and the growing range of threats often outweigh the security department's resources.

If the security industry is to progress, it will occasionally have to step away from technological problems and wrestle with some of these types of people problems. How to fund, find, and keep good security people. How to teach end users not to click on suspicious attachments. How to build security policies that are realistic for the business, yet also enforceable by monitoring and security controls.

These issues won't be solved at the conference next week, but it's good to see security professionals working on them together. Cybercriminals are famous for sharing (and stealing) each other's ideas and techniques, and that sharing has helped them to get an edge on enterprise defenders. Anytime security professionals get together to share their knowledge -- whether in small groups or at a major conference -- it improves the enterprise's chances of successfully fighting back. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Thomas Ianuzzi
50%
50%
Thomas Ianuzzi,
User Rank: Apprentice
9/27/2013 | 3:23:41 PM
re: (ISC)2 Congress Addresses Security's People Problems
I am delighted to see you highlighting the most common problem I've seen in security over the years. While the technical problems are constantly are a moving target, the people problems are the gift that keeps on giving to attackers.
Tom Ianuzzi
President
Information Security Consultants, Inc.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.