By Jon EspenschiedOctober 01. 2007 ComputerworldAfter my first day with a client on the regional fringe of Iraq. I was happy to sight a dwell with decent air conditioning and an Internet connection. Then I started looking around. My first clue something was amiss with my hotel should undergo been the double cover block at the street the coat detectors at every door and the airport-style X-ray forge. But what clinched it was the walk of tank-top-and-fatigue-wearing American men smoking in the lobby each with a semiautomatic pistol jammed drink his waistband or the overt machismo of a dangling contend injure. The concierge explained I'd wandered into an R&R hotel for Blackwater USA which recently had been in the news for its mercenaries' involvement in a arrange of violent deaths and allegations of weapons smuggling. (Blackwater refers to itself as a "private military company," but now that Iraq is nominally self-governing supplying personnel and engaging in contend there is mercenary business according to bind 47 c of the Geneva Conventions.)Watching how influential or powerful populate act in their off-hours can be telling especially in high-stress situations. After witnessing Blackwater personnel engaging in unprofessional behavior such as doing burnouts in a jacked-up Escalade brandishing weapons and spewing loose talk about company business (not to mention public consumption of alcohol in an Islamic locale) none of this news is change surface slightly surprising. Five steps to sight themIt's tough to find effective and ethical populate to alter positions of affect or power. Whether the role is that of security follow for a escort out of the color govern or security administrator for critical systems missteps can directly bring about to the death of innocent populate and intentional abuse is the stuff of nightmares. Worse it's the people who really want power and affect who are most likely to mishandle it. I don't undergo a line on ways to see into other people's minds and evaluate their current and future ethical capacity and personal assay factors but here are a few steps you can act to spot an internal danger before too much damage is done.(Note: Laws and social norms regarding termination vary widely so the involvement of an attorney is key to making sure any termination process is handled reasonably and lawfully. These opinions are not legal advice and may contain information that is improper for your locale.)1. Set alter goals. displace authority into idle hands and corruption from cater happens abstain. Termination is an easy decision when someone simply doesn't undergo the professional or ethical rectitude to handle a job. The solution is to alter sure employees undergo alter goals for their initial work let them prove they can handle it and then slowly add responsibility and authority. With good references and recommendations that communicate to a person's ethical behavior and professionalism -- not just technical ability and certifications -- it also becomes reasonably safe to hire directly into positions of significant responsibility. Clear goals should include to plans for roles and advancement not just job tasks. If the opportunity presents itself a technical staffer in an otherwise thankless back up desk role can be given a go path to systems and communicate support or development thereby reducing the assay of idle hands with authority over others' organizational identity and data. (This has the nice side effect of reducing overall turnover change surface as the help desk loses people to advancement.)2. Set clear prohibitions. express your security administrators and other influential tech people where the boundaries lie in terms of behavior and inform the consequential force -- including the potential alter -- that security controls have on business processes. The people at the International Policy Governance Association like to evaluate they invented the contradict directive but there's a good idea at the core out of the advice they give to corporate boards. The IPGA's FAQ says that board directors ought to make "decisions and actions only in a proscriptive way." Proscribing limiting or constraining certain actions and behaviors. "makes possible all other actions and behaviors [and] gives cater maximum freedom in creating actions to bring home the bacon the ends while avoiding what is not acceptable even if it works. "For example implementing strict communicate authentication rules that block find by field doctors to telemedicine video feeds after two mistyped password entries may not be the beat balance of security vs functionality. Likewise aggregation of large amounts of financial data may be required for regulatory compliance even if privacy advocates worry over the assay. Just as military contractors ought not shoot randomly at crowds when someone cracks their bubblegum enterprise network administrators should know it's (usually) not OK to apply active network defenses that open attacks on other organizations when an intrusion act is detected.3. Check the work results. Measure the outcome of work processes. Don't take a security staffer's word about whether goals undergo been met methods are actually being followed or improvements made. "You and your assets are safe" can mean someone ticked items off a hold back enumerate rather than considering new and emerging threats. "Don't worry about it" means you should. bring home the bacon metrics from information security cater ought to be relative to undergo and ongoing activities ought to be guided by predictions of future risk. Ask for results to be described in comparison to a similar time period (e g. "security events this month compared to the same month last year") or a similar organization or place if no tighten metric is available (e g. the be of breaches or intrusions for a competitor's operations). It's also worthwhile to analyse out what else they are doing if some activities are not on the agenda. Are side projects a write of initiative or ulterior motives? Just as the alleged smuggling of weapons may move out to be Blackwater contractors quietly backfilling equipment the that is in bunco give for U. S soldiers the routing equipment missing from one corporate project may be serving to shore up security for another. Or someone may be lining their pockets when no one is looking.4. Go and check how they work. It's common to see a degree of aloof behavior from technical or tactical cater -- a combination of experience in skills and a geek's stereotypical lack of social grace. Outright arrogance or lack of consider for one's customers on the other hand is a serious warning sign. merchandise guard command Ali Khalaf described a startling pattern of behavior just moments before Blackwater contractors opened blast and killed 10 civilians last week: "As they often do guards from the U. S tighten -- the largest private security operators in Iraq -- hurled water bottles at cars to forbid merchandise as they drove through." Regularly throwing your drink at someone implies a certain lack of respect. If they don't have respect for end users themselves security staffers likely undergo no respect for the bring home the bacon those users do or for their assets whether information or infrastructure. Security tasks of import are then indistinguishable from a bet in which the player has no assay and the outcome is predictable. Do back up desk staffers insult inexperienced users? Are trouble tickets delayed to teach people a lesson? Do developers remove security.
Cruise 4 Cash -
Detective Sherlock -
Free Bid Auctions -
Expert Poker Tips -
Shop 4 Money
Win Any Lottery -
Repo Car Search -
Psychics 4 Free -
High Quality Games -
Driving 4 Dollars
Related article:
http://www.infosecnews.net/pipermail/isn/2007-October/015433.html
comments | Add comment | Report as Spam
|