The Biggest Problem in Computer Security
Posted on Saturday, November 03, 2012 by Tenderfoot
The Biggest Problem in Computer Security
People tend to focus on various areas as being important for
computer security such as memory corruption vulnerabilities, malware, anomaly
detection, etc. However the lurking and most critical issue in my opinion is
staffing. The truth is, there is no pool of candidates out there to draw from
at a certain level in computer security. As an example, we do a lot of
consulting, especially in the area of incident response, for oil & gas,
avionics, finance, etc. When we go on site we find that we have to have the
following skills:
1. Soft skills. (often most important) The ability to talk
to customers, dress appropriately, give presentations or speak publicly, assess
the customer staff, culture and politics, and determine the real goals. I can't
stress enough how important this is. It's not the 90s anymore, showing up with
a blue mohawk, a spike in the forehead and leather pants, not a team player,
cussing and surfing porn on the customers system doesn't cut it no matter how
good you are technically. If you are that guy then you get to stay in the lab
and I guarantee you will make far less money. Even if you can write ASLR bypass
exploits and kernel rootkits.
Subscribe to:
Post Comments (Atom)
No Response to "The Biggest Problem in Computer Security"
Leave A Reply