Posts

Showing posts with the label ethics

COVID-19 Phishing Tests: WRONG

Malware Jake Tweeted a poll last night which asked the following: "I have an interesting ethical quandary. Is it ethically okay to use COVID-19 themed phishing emails for assessments and user awareness training right now? Please read the thread before responding and RT for visibility. 1/" Ultimately he decided : "My gut feeling is to not use COVID-19 themed emails in assessments/training, but to TELL users to expect them, though I understand even that might discourage consumption of legitimate information, endangering public health. 6/" I responded by saying this was the right answer. Thankfully there were many people who agreed, despite the fact that voting itself was skewed towards the "yes" answer. There were an uncomfortable number of responses to the Tweet that said there's nothing wrong with red teams phishing users with COVID-19 emails. For example: "Do criminals abide by ethics? Nope. Neither should testing." "Ye...

Corporate Digital Responsibility

Image
I've started listening to the Economist Audio Edition on my iPod while running. Last week I listened to a special report on Corporate Social Responsibility . I was struck by the language used and issues discussed in the report. Here are a few excepts. First, from Just good business : Why the boom [in CSR initiatives]? For a number of reasons, companies are having to work harder to protect their reputation — and, by extension, the environment in which they do business... CSR is now made up of three broad layers, one on top of the other. The most basic is traditional corporate philanthropy... [T]he second layer of CSR... is a branch of risk management ... So, often belatedly, companies respond by trying to manage the risks. They talk to NGOs and to governments, create codes of conduct and commit themselves to more transparency in their operations. Increasingly, too, they get together with their competitors in the same industry in an effort to set common rules, spread the risk an...

Who Needs CISSP for Ethics?

Last year I discussed the value of the CISSP with respect to its code of ethics . Today while renewing my ISSA membership, I was presented with the following: The primary goal of the Information Systems Security Association, Inc. (ISSA) is to promote practices that will ensure the confidentiality, integrity, and availability of organizational information resources. To achieve this goal, members of the Association must reflect the highest standards of ethical conduct. Therefore, ISSA has established the following Code of Ethics and requires its observance as a prerequisite for continued membership and affiliation with the Association. As an applicant for membership and as a member of ISSA, I have in the past and will in the future: * Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles; * Promote generally accepted information security current best practices and standards; * Maintain appropriate confident...

Should I Accept New ISC(2) Certification Agreement?

Today I received an email from the International Information Systems Security Certification Consortium, Inc. , ISC(2), that read, in part: "The purpose of this notice is to provide information regarding the status of your (ISC)² certification. Our records indicate that your anniversary date is near and your Annual Maintenance Fees are current. As you are aware, a total of 120 Continuing Professional Education (CPE) credits, of which at least 80 must be Type 'A' credits, are required to be submitted during each three year certification period in order to maintain your credential. Our records indicate that, based upon your CPE submissions to date, you are not on track to meet your recertification requirements at the end of the three year period. We urge you to pay close attention to this matter to avoid the expiration of your CISSP credential." OH NO! Time for me to log in to the ISC(2) Web site to record in some of the hundreds of CPEs I haven't logged. Howeve...

CISSP: Any Value?

A few of you wrote me about this post by Thomas Ptacek in response to my recent CISSP exam post. Tom has one of the best minds in the security business, and I value his opinions. Here are my thoughts on the CISSP and an answer to Tom's blog. (I did not realize Tom has despised the CISSP for so long!) On page 406 of my first book I wrote: "I believe the most valuable certification is the Certified Information Systems Security Professional (CISSP). I don't endorse the CISSP certification as a way to measure managerial skills, and in no way does it pretend to reflect technical competence. Rather, the essential but overlooked feature of the CISSP certification is its Code of Ethics... This Code of Ethics distinguishes the CISSP from most other certifications. It moves security professionals who hold CISSP certification closer to attaining the true status of 'professionals.'" In my book I compared the CISSP Code of Ethics to the National Society of Professio...

(ISC)2 Conducting CISSP Exam Survey

Image
Last month I reported a friend's experiences with the CISSP exam. This week I received an email from (ISC)2 regarding a survey of the CISSP exam. It reads in part: "(ISC)2 would like to extend to you the opportunity to provide key input into the content of the CISSP® examination. With assistance from Schroeder Measurement Technologies, Inc., (ISC)2’s services entity,(ISC)2 is conducting a CISSP job analysis study through an online survey. The purpose of the job analysis study is to ensure the currency of future CISSP examinations. As a CISSP certificate holder, we are asking you to participate in the survey. *Your responses are valued and essential*. We ask that you set aside 20 to 30 minutes of your time no later than Thursday, July 14, 2005 to complete the online survey." Once I started taking the survey, I saw these guidelines. "A comprehensive list of important job tasks performed by an Information Systems Security Professional is presented on the following...

Report from the CISSP Exam

No, I did not take the CISSP test again -- thank goodness. A friend of mine just did, however. He agreed to share his story with you. "I attended the Intense School CISSP bootcamp last week and took the test last Sunday. I received my test result today and I passed! It was the hardest and most obscure test I have ever taken. I was convinced I did not pass. Usually, I perform well on test, but this was a monster. I never want to take it again and wouldn’t wish my version of the test on anyone! It took me two hours and 50 minutes. I guess that is fast compared to the average. I can’t imagine sitting there for six hours staring at those questions. I just answered/guessed and moved on and didn’t go back and change any answers. I think I was the first CISSP test taker done in the room. I am so relieved." I had the same experience almost four years ago, except I finished in 90 minutes. The room was so cold, I just wanted to be done and get out of there as fast as pos...

What Makes For Credible Certifications?

Peter Stephenson contributed to a SC Magazine article that featured criteria for credible certifications. I found his comments worthwhile: "The major question to be asked about certifications and their value is: 'Where does the cert come from and what are its objectives?' A good industry certification will have several recognizable components if it is to be credible: It is based upon an accepted common body of knowledge that is well understood, published and consistent with the objectives of the community applying it. It requires ongoing training and updating on new developments in the field. There is an an examination (the exception is grandfathering, where extensive experience may be substituted). Experience is required. Grandfathering is limited to a brief period at the time of the founding of the certification. It is recognised in the applicable field. It is provided by an organization or association operating in the interests of the community, usually non-profit, no...

New "CISSP Associate" for People without Years

I learned today that people who would like to be a CISSP without having the necessary number of years experience can become a CISSP Associate . I find this rather odd. According to the press release: "After passing the selected exam and signing (ISC)2's Code of Ethics, the Associate must garner the requisite work experience and successfully complete a professional endorsement process before he/she becomes officially certified as CISSP or SSCP. The CISSP, designed for professionals devising information security strategy, requires four years of professional experience in the field of information security, while the SSCP, designed for professionals following a tactical information security career path, requires one year of experience. Associates of (ISC)2 will not be able to use the designation of CISSP or SSCP until formally certified." Why bother, then? Is this "CISSP-lite"? I think it's a ploy to get more people to take the exam and say "Yes, pro...

Problems with CISSP Questions

The June 2003 Information Security Magazine offered some great reading too. It reminded me of a Gartner statistic saying between 60 to 70 percent of Windows Server users run NT 4 . Writing about his experience taking the CISSP exam, Andrew Briney nails the problem with CISSP questions : "There's a chunk of questions that are difficult for all the wrong reasons. They're poorly worded, misleading or simply evasive. Evasive: that's the word that first came to mind when I walked out of the exam. It just seems like these questions serve no purpose other than to confuse and frustrate you. It's because of these questions that you won't have an intuitive sense if you passed the exam. And it's because of these questions that the CISSP exam often gets a bad rap. Even though these questions comprise a comparatively small part of the exam, they're the ones that stick in your craw as you walk out the door." I learned while reading Thomas Ptacek's ...

(ISC)2 Developments

I learned the NSA is teaming up with (ISC)2 to create the Information Systems Security Engineering Professional (ISSEP) certification. According to the press release: [The] (ISSEP) credential [is] for information security professionals who want to work for NSA, either as employees or outside contractors. The new certification will serve as an extension of the CISSP. . . The new domains of the ISSEP will focus on the technical knowledge required of government information systems security engineers such as ISSE processes and government regulations. The ISSEP complements the CISSP by comprehensively addressing the systems engineering side of information security. I like the idea of addressing security "systems engineering," if they follow the ideas of Ross Anderson . I don't find the "government regulations" aspect appealing. On 16 Apr ISC(2) announced two "concentrations" for CISSPs: "the CISSP, Management Concentration and CISSP, Architec...

National Society of Professional Engineers Code of Ethics

This Slashdot post brought to my attention the National Society of Professional Engineers Code of Ethics , which should apply to IT consultants as well. It includes: I. Fundamental Canons Engineers, in the fulfillment of their professional duties, shall: Hold paramount the safety, health and welfare of the public. Perform services only in areas of their competence. Issue public statements only in an objective and truthful manner. Act for each employer or client as faithful agents or trustees. Avoid deceptive acts. Conduct themselves honorably, responsibly, ethically, and lawfully so as to enhance the honor, reputation, and usefulness of the profession. Codes of ethics are the only worthy element of the "certification" I hold -- the CISSP. Here is its Code : Protect society, the commonwealth, and the infrastructure. Act honorably, honestly, justly, responsibly, and legally. Provide diligent and competent service to principals. Advance and protect...