Perimeter
12/5/2011
10:32 AM
Mike Rothman
Mike Rothman
Commentary
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Work And Play In Security

As we look toward 2012, it's time to have more fun at work

Security folks tend to be a pretty grumpy lot. The reasons behind that are pretty obvious, since many practitioners get marginalized because security doesn't really contribute to either the top or bottom lines of an organization. I mean, a breach can impact both, but there is no assurance of a breach or any assurance that investment will prevent a breach. So the entire security house of cards is based on the fact that investments are made to stop something that might or might not happen. And we wonder why the clear impact of a compliance fine drives so much investment is security controls nowadays?

It doesn't help that there is no real "win" for a security practitioner. Today the attackers might not achieve their objectives, but there is always tomorrow. What about doing some kind of security awareness? Yeah, most think that's futile as well. Most folks think of security as a burden and behave accordingly. Looking ahead toward 2012, I'm done with predicting. Yeah, things will be worse. Or not. We'll get more budget. Or not. We'll be breached. Or ... OK, that will happen. Given that my crystal ball is not retired, let's think a bit more tangibly. We need to have more fun in 2012.

You know the old saying, "All work and no play makes Jack a dull boy." Guess what? You're Jack. We all are. That's the nature of the job. But that doesn't mean we can't be more active about making our day-to-day existence a little less miserable. Then I read this post on the New School blog positing :The Future of Work is Play." It makes perfect sense. But how does that apply to security, where "play" isn't usually a word you'd associate with the discipline? I can think of a few ways off of the top of my head:

1. Awareness Games: Nobody like security-awareness training. Most folks tune out within the first five to ten minutes, but they check the box and then proceed to get owned at every turn. What if we turned the security awareness into a game? Try a scavenger hunt with prizes for folks who can detect which emails are phishing, or those who don't click on a bad link. OK, it's not Gears of War, but it's not like you can make awareness training less effective. So try to have some fun with it.

2. Friendly Competitions: Most of you have trouble getting developers to code securely. Why not try a contest? Any developer who has no code flagged for security issues each month gets a night out on the town, courtesy of the security team. Or provide a bounty for out-of-the-box thinking during a threat-modeling exercise. Given what it costs you to clean up the mess when crappy, insecure code gets shipped, this would be a good investment.

3. Capture The Flag: You need to be doing incident-response exercises anyway, and we have always been fans of pen tests to keep your folks on their toes. Why not organize a capture the flag exercise on your own networks? OK, there would need to be some rules of engagement (like not taking down the website), but offer up some prizes and create some competition. Folks love competition, and they also like being able to give their teammates a hard time. As long as the razzing is all in good fun, this can again be a cheap way to keep folks engaged.

I'm sure there are a ton of other ideas to add a little more play to our jobs in security. It probably can't get less fun, so what do you have to lose? And you get to watch the reaction of your significant other when you tell him or her you played games all day at work. Sounds like a great idea to me. Happy holidays, y'all, and I'm looking forward to Hacking Off some more in 2012.

Mike Rothman is President of Securosis and author of the Pragmatic CSO. Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-0360
Published: 2014-04-23
Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

CVE-2012-1317
Published: 2014-04-23
The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.

CVE-2012-1366
Published: 2014-04-23
Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.

CVE-2012-3062
Published: 2014-04-23
Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a network that contains many IPv6 hosts, aka Bug ID CSCtr88193.

CVE-2012-3918
Published: 2014-04-23
Cisco IOS before 15.3(1)T on Cisco 2900 devices, when a VWIC2-2MFT-T1/E1 card is configured for TDM/HDLC mode, allows remote attackers to cause a denial of service (serial-interface outage) via certain Frame Relay traffic, aka Bug ID CSCub13317.

Best of the Web