Dr. Anton asks the question "Where do you draw the line: Security Responsibility?" Well this time the answer isn't "It depends". The way I read the question after reading his post is, Where does the buck stop? The buck stops here. It stops with us. It is our job to secure the environment and part of that job is to ensure that the users know how to practice security.
It would be ridiculous for IT or Security to have 100% responsibility. If we did then things would be locked down so tight that the users couldn't get anything done. If we gave them all of the responsibility then we might as well pack up and go home. That is unless you want to spend your days playing PC clean up or pushing out new Images every few days.
We shoulder most of the burden. It's our responsibility to make sure that the systems are hardened and that the controls are in place and that the policies (both written and system) are effective and to get as much information to the users as possible so that they can do their job (and even their play time) securely. If you have done all you can with what you are given and a system gets owned then it's not your fault (your boss may think otherwise, just tell them to talk to me). If you haven't done all you can and you get owned then it doesn't matter what the user did you are responsible. Users are like little children. We can't send them out into the big bad world without preparing them and expect them to escape unscathed.
So how does Dr. Anton's equation really look? Probably something like Security=85%, IT=10% and Users=5%. We build the security program, create the policies, train the users (and IT), set the rules. IT follows the policies and procedures that come from us. They build the systems according to spec and ensure that the infrastructure works as it should. Then the users do their part and the users do their part and play it smart and safe. Then we are all happy, safe and secure. That is a recipe for information security ala mode.
Security's Everyman
Thursday, August 30, 2007
Where Does the Buck Stop
Posted by
Andy, ITGuy
at
10:28 PM
1 comments
Labels: Andy ITGuy, Dr. Anton, information security, user awareness
Monday, January 22, 2007
The Value of Best Practices
Update: I'm unofficially changing the title of this post to "The Value of Checklists". I originally wrote this at about 5:00am this morning and the words best practices were in Dr. Anton's post and the morning fog carried them over to my title. Thanks to Mike for pointing out that Checklists and Best Practices are not the same thing.
____________________________________________________________________
Dr. Anton and Ross Brown talk about the benefits of just plain good security over just following the check list to be compliant or just for the sake of doing something. I couldn't agree more, but we have to be careful that our desire to see people practice good security doesn't discourage them from doing something that can help secure our networks. Checklists do have a place in security. They remind us of things that we need to do each and every day. Without them we will get caught up in the fires and emergencies of each day and overlook something that may be happening that needs our attention. They also keep us accountable to do a good job. Security professionals need accountability to management and users to show that we are doing our job. It's easy to say that we do our jobs because if we didn't then there would be lots of problems, but that doesn't always fly with management. As much as I dislike checklists they do have their place and we need to encourage the use of them. Not as proof that we are secure and surely not as the "key" to being secure, but to help us remember the little things that we often forget and to keep us aware of all that we have to do to have a secure environment.
Posted by
Andy, ITGuy
at
10:03 PM
1 comments
Labels: Dr. Anton, information security, technobabylon
