I don’t like the term “Best Practices.” Andrew and I railed against it in the book (pages 36-38). I’ve made comments like “torture is a best practice,” “New best practice: think” and Alex has asked “Are Security “Best Practices” Unethical?“ But people keep using it. Worse, my co-workers are now using it just to watch [...]
Filed under: Amusements, best practice, Doing it Differently by adam on Friday, February 12, 2010
15 Comments »
Since writing the New School, I’ve been thinking a lot about why seems so hard to get there. There are two elements which Andrew and I didn’t explicitly write about which I think are tremendously important. Both of them have to do with the psychology of information security. The first is that security experts are [...]
Filed under: best practice, Uncategorized by adam on Monday, January 4, 2010
3 Comments »
Someone sent me a link to “How to Audit-Proof Your Tax Return: Don’t e-File,” by Paul Caron. In it he quotes a plausible theory that “you are giving the IRS easy electronic access to information it would otherwise have to enter, enabling the agency to examine your return and mine the data more easily than [...]
Filed under: best practice, Uncategorized by adam on Thursday, November 12, 2009
6 Comments »
In comments yesterday, both Kyle Maxwell and Nicko suggested that “standard” is a better adjective than “proven:” I like Kyle’s “standard” practice, since it makes it clear that you are just following the flock for safety by sticking to them. Perhaps we should call them “flocking standard practice” I do think there’s an important difference, [...]
Filed under: best practice, Uncategorized by adam on Wednesday, November 11, 2009
3 Comments »
After I posted the new Best Practice: Think, Dennis Fisher tweeted “Never catch on. Nothing for vendors (or Gartner) to sell.” Which is true, but that’s not the point. The point is to be able to ju-jitsu your best-practice cargo-culter into submission. For example: Cargo-culter: We don’t need a review, this project complied with all [...]
Filed under: best practice, Uncategorized by adam on Tuesday, November 10, 2009
2 Comments »
Anton Chuvakin’s been going old school. Raising the specter of “risk-less” security via best practices and haunting me like the ghost of blog posts past. Now my position around best practices in the past has been that they are, to use Jack Jones’ phrase, Infosec “shamansim”. We do these things because our forefathers do them, [...]
Filed under: best practice, Uncategorized by alex on Friday, October 16, 2009
11 Comments »
Since anyone can declare anything a best practice in information security, I’d like to add my favorite to your list. Think. Thank you.
Filed under: best practice, Uncategorized by adam on Wednesday, October 14, 2009
8 Comments »