Perimeter
12/5/2011
10:32 AM
Mike Rothman
Mike Rothman
Commentary
50%
50%

Work And Play In Security

As we look toward 2012, it's time to have more fun at work

Security folks tend to be a pretty grumpy lot. The reasons behind that are pretty obvious, since many practitioners get marginalized because security doesn't really contribute to either the top or bottom lines of an organization. I mean, a breach can impact both, but there is no assurance of a breach or any assurance that investment will prevent a breach. So the entire security house of cards is based on the fact that investments are made to stop something that might or might not happen. And we wonder why the clear impact of a compliance fine drives so much investment is security controls nowadays?

It doesn't help that there is no real "win" for a security practitioner. Today the attackers might not achieve their objectives, but there is always tomorrow. What about doing some kind of security awareness? Yeah, most think that's futile as well. Most folks think of security as a burden and behave accordingly. Looking ahead toward 2012, I'm done with predicting. Yeah, things will be worse. Or not. We'll get more budget. Or not. We'll be breached. Or ... OK, that will happen. Given that my crystal ball is not retired, let's think a bit more tangibly. We need to have more fun in 2012.

You know the old saying, "All work and no play makes Jack a dull boy." Guess what? You're Jack. We all are. That's the nature of the job. But that doesn't mean we can't be more active about making our day-to-day existence a little less miserable. Then I read this post on the New School blog positing :The Future of Work is Play." It makes perfect sense. But how does that apply to security, where "play" isn't usually a word you'd associate with the discipline? I can think of a few ways off of the top of my head:

1. Awareness Games: Nobody like security-awareness training. Most folks tune out within the first five to ten minutes, but they check the box and then proceed to get owned at every turn. What if we turned the security awareness into a game? Try a scavenger hunt with prizes for folks who can detect which emails are phishing, or those who don't click on a bad link. OK, it's not Gears of War, but it's not like you can make awareness training less effective. So try to have some fun with it.

2. Friendly Competitions: Most of you have trouble getting developers to code securely. Why not try a contest? Any developer who has no code flagged for security issues each month gets a night out on the town, courtesy of the security team. Or provide a bounty for out-of-the-box thinking during a threat-modeling exercise. Given what it costs you to clean up the mess when crappy, insecure code gets shipped, this would be a good investment.

3. Capture The Flag: You need to be doing incident-response exercises anyway, and we have always been fans of pen tests to keep your folks on their toes. Why not organize a capture the flag exercise on your own networks? OK, there would need to be some rules of engagement (like not taking down the website), but offer up some prizes and create some competition. Folks love competition, and they also like being able to give their teammates a hard time. As long as the razzing is all in good fun, this can again be a cheap way to keep folks engaged.

I'm sure there are a ton of other ideas to add a little more play to our jobs in security. It probably can't get less fun, so what do you have to lose? And you get to watch the reaction of your significant other when you tell him or her you played games all day at work. Sounds like a great idea to me. Happy holidays, y'all, and I'm looking forward to Hacking Off some more in 2012.

Mike Rothman is President of Securosis and author of the Pragmatic CSO. Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.