3B The Importance of Being Earnest

No ratings

Presented at COSAC 2015 by

"We should treat all trivial things in life very seriously, and all serious things of life with a sincere and studied triviality." Security is not just technology, it is also human activity and organizational culture. Traditions of security tend to be formal and well defined, and to be taken seriously a security specialist of spokesman is expected to behave in a certain manner. Some of the early traditions inherited from physical security community may have changed, but has the information security community developed new rigid rules which a security practitioner must follow in order to be considered earnest enough? Inspired by Oscar Wilde’s brilliant satire of Victorian earnestness, the speaker analyses the culture of information security community. The subject is discussed form different points of view in various contexts: Security practitioner interfacing with his/her organization, customers, media, … Security team in an organizational context, Security associations, Security conferences, National or international security authorities, … and many others. This presentation may be fun, but it is not for fun only. It is fundamentally earnest in its objective to shed some light on potentially harmful cultural aspects of the security profession – behaviours which may undermine the important risk management objectives of security.