The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Should the CISSP CBK be expanded to cover "human factors" in security? iBot IT Security RSS 0 08-10-2009 07:15 AM
A question/problem about oracle "tns listener" and "enterprise manager" talipk UNIX for Advanced & Expert Users 1 12-03-2008 07:55 AM
Development Releases: Linux Mint 4.0 Beta "Fluxbox", 4.0 Alpha "Debian" iBot UNIX and Linux RSS News 0 01-04-2008 03:00 PM
Explain the line "mn_code=`env|grep "..mn"|awk -F"=" '{print $2}'`" Lokesha UNIX for Dummies Questions & Answers 4 12-20-2007 01:52 AM
No utpmx entry: you must exec "login" from lowest level "shell" peterpan UNIX for Dummies Questions & Answers 0 01-18-2006 04:15 AM

 
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 08-11-2009
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,193
Add "human factors"? No.

OK, Gary has asked if the CISSP CBK should be expanded to cover "human factors" in security?

And I answer "No."

With that kind of beginning, you could be forgiven for thinking that I disagree with Gary about the importance of human factors in security.  Nothing could be further from the truth.  I agree with everything he has said about the fundamental significance of human factors in information security, as well as the difficulty of dealing with them, and will defend to the death his right to say it.

What I disagree with is the question.

The CBK already addresses human factors.

When I teach CBK review seminars, I start with the security management domain.  Yes, Gary is right that this field started out with a bunch of technical people who had difficulty understanding that people don't always do what you tell them.  So candidates coming in, who are not prepared for dealing with human factors, get a good scare right off the top.  They have to deal with management, which means dealing with people (and probably politics).  And organizational roles (which have to do with people).  And security awareness training. (Oh, and ethics.)

Moving on to access control, we talk about social engineering there.  (As well as the password choice problem Gary mentioned.)  Good scope for human factors.

Crypto's a technical field, so no human factors, right?  Wrong.  We talk about implementation problems, and the inability of people to be truly random.

Physical security talks about human factors.

BCP talks about human factors.  As long as you are truly recovering the business, as you should be, and not just systems.  (Common mistake.)

Security architecture is pretty technical.  But it deals with the security frameworks, with all those guideline documents.

Applications security has a lot to do with human factors.  (If you actually do it properly.)

Telecom?  Sure, that's technical.  But it also has to do with spam, social networking, phone phreaking, and all kinds of social engineering/human factors implications.

Operations?  You're dealing with people.  In fact, most of the stuff in operations could equally be dealt with in other domains, except for the extra provisions you have to make for your employees who need escalated privileges.  Your classic insider situation.

Law and investigation?  If you don't think that is mostly dealing with human factors, you are in the wrong field.

So, no, the CBK doesn't need to have human factors added.

If you want to talk about whether we need to pull all the human factors stuff out, and put it in a separate domain, that's a different question.

(And, to that one too, I'd say no.  We'd have a human factors domain that takes up three days of a five day seminar, and have to squish the existing domains into the remaining two days.)




More...
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 08:52 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0