Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

(ISC)2 Congress Addresses Security's People Problems

Annual (ISC)2 conference puts technology aside to focus on the human side of security

There are many conferences and get-togethers around cybersecurity every year, but only a few would be considered "mandatory" by the whole community of security professionals. The RSA Conference, held each year in San Francisco, offers the industry's biggest exhibit floor and a chance to see security products in action. Black Hat USA, held annually in Las Vegas, is where the smartest and best security researchers come to reveal vulnerabilities and share knowledge on potential threats.

While these events offer a depth of technological insight unmatched in IT security, though, they don't necessarily focus on the "people" issues faced every day by the average security professional. That's why I'll be in Chicago next week for the third annual (ISC)2 Security Congress, the yearly meeting of the world's biggest cybersecurity professionals' organization.

(ISC)2's Congress -- held concurrently with ASIS, the granddaddy of physical security conferences -- doesn't have an overriding technological "theme" because it isn't focused on technology. Its focus is discussing the day-to-day, nonsexy issues that all security professionals grapple with, such as staffing, hiring, management, and administration. Where other events might have more of a "show" of leading-edge technology or new threats, (ISC)2 is more like a water-cooler conversation among colleagues faced with similar security problems and issues.

Meetings of security professional organizations, such as (ISC)2, ISSA, and ISACA, represent the "everyman" infosec pro, who may not always be up on the most current products or attacks because he or she is fighting the everyday fires of the enterprise. These are people who work in the trenches of security and are limited by time, budgets, and short staffing. They spend a frustrating amount of time in meetings, arguing with top executives or end users who don't understand the dangers their systems face every day. Their job is not to be on the leading edge, but to get their data secure as best they can with what they've got.

This year, many of (ISC)2's sessions will focus on how to do more with less, how to train staffers and end users to improve enterprise defenses, and how to make tough decisions about security in a rapidly changing environment where the needs of the business and the growing range of threats often outweigh the security department's resources.

If the security industry is to progress, it will occasionally have to step away from technological problems and wrestle with some of these types of people problems. How to fund, find, and keep good security people. How to teach end users not to click on suspicious attachments. How to build security policies that are realistic for the business, yet also enforceable by monitoring and security controls.

These issues won't be solved at the conference next week, but it's good to see security professionals working on them together. Cybercriminals are famous for sharing (and stealing) each other's ideas and techniques, and that sharing has helped them to get an edge on enterprise defenders. Anytime security professionals get together to share their knowledge -- whether in small groups or at a major conference -- it improves the enterprise's chances of successfully fighting back. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Thomas Ianuzzi
50%
50%
Thomas Ianuzzi,
User Rank: Apprentice
9/27/2013 | 3:23:41 PM
re: (ISC)2 Congress Addresses Security's People Problems
I am delighted to see you highlighting the most common problem I've seen in security over the years. While the technical problems are constantly are a moving target, the people problems are the gift that keeps on giving to attackers.
Tom Ianuzzi
President
Information Security Consultants, Inc.
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
5 Common Errors That Allow Attackers to Go Undetected
Matt Middleton-Leal, General Manager and Chief Security Strategist, Netwrix,  2/12/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-7505
PUBLISHED: 2020-02-18
Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.
CVE-2015-7567
PUBLISHED: 2020-02-18
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.
CVE-2012-0718
PUBLISHED: 2020-02-18
IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.
CVE-2019-10791
PUBLISHED: 2020-02-18
promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.
CVE-2009-5146
PUBLISHED: 2020-02-18
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.