Pick a side. You either want your employees to have a work/life balance, or you want them to be obsessed with security 24/7. You can’t have both.
Thanks to this week’s podcast sponsor, StackRox
Got feedback? Join the conversation on LinkedIn.
On this week’s episode
What would you advise?
People speak a lot about the importance of integrating security and DevOps. Now it’s time to learn some specifics, like how to energize developers to be more security minded in their development. What works? What hasn’t worked?
You just learned something was breached. Uggh. (Thanks to Mike Toole, Censys)
What’s the best way to handle this ?
What questions should be asked to see if a security team is cloud incident ready? A good article over on F5 by Sara Boddy, Raymond Pompon, and Sander Vinberg, provides some suggestions such as “Can you describe our attack surface and how have you reduced it to the bare minimum?” and “How are we managing access control?” and “What do we do when systems or security controls fail?” Which of the questions is the most revealing to cloud security readiness and why?
Should you ignore this security advice?
On the AskNetSec subreddit someone inquired about a good hiring question. One redditor suggested asking “What do you do on your own home network with respect to security?” to which another redditor argued that the question was unfair. He left the security and networking for work. He had other hobbies and interests for home life. Another person said, yes it is unfair, but there are plenty of candidates who do breathe security 24/7 and if given a choice, the redditor would take that person. The politically correct thing to say is you want the person with the work-life balance, but wouldn’t we be more impressed with the person who has security in their blood day and night?
Close your eyes and visualize the perfect engagement
Another question on AskNetSec subreddit asked “What are the most important skills you see missing among other coworkers or your team?” The two most common answers I saw on the thread were communications and critical thinking. Are these correct. or should something else go there? ? And if those two did improve, what would be the resulting effect to a company’s security program?
Image photo credit:
(CC BY 2.0) Flickr user Brandon Giesbrecht.