<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Background checks? We don' need no background checks ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11486#M1107</link>
    <description>&lt;P&gt;In Florida (which, you will recall, had recent mass shootings such as at the Stoneman Douglas High School and the Pulse nightclub) more than a year went by in which &lt;A href="https://nakedsecurity.sophos.com/2018/06/12/florida-skips-gun-background-checks-for-a-year-after-employee-forgets-login/" target="_blank"&gt;the state approved gun carry licence applications without carrying out background checks&lt;/A&gt;.&amp;nbsp; The reason? An employee couldn't remember her login for the check system.&amp;nbsp; So she just didn't check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am reminded of a situation where sales and marketing was supposed to carry out virus scans before they installed our product.&amp;nbsp; They had previously been using an inferior product and I mandated that they using a more accurate product.&amp;nbsp; At one point a machine was brought in as a problem.&amp;nbsp; First step in my process was to scan the machine, and, sure enough, it was infected.&lt;/P&gt;&lt;P&gt;"Did you scan it?"&lt;/P&gt;&lt;P&gt;"Yes."&lt;/P&gt;&lt;P&gt;"Did you use the right scanner?"&lt;/P&gt;&lt;P&gt;"Well, no, we used the old one."&lt;/P&gt;&lt;P&gt;"Why did you use the old scanner, when I've specified that you have to use the new one?"&lt;/P&gt;&lt;P&gt;"Well, when we use the one you told us to, it finds viruses ..."&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 08:49:14 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2023-10-09T08:49:14Z</dc:date>
    <item>
      <title>Background checks? We don' need no background checks ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11486#M1107</link>
      <description>&lt;P&gt;In Florida (which, you will recall, had recent mass shootings such as at the Stoneman Douglas High School and the Pulse nightclub) more than a year went by in which &lt;A href="https://nakedsecurity.sophos.com/2018/06/12/florida-skips-gun-background-checks-for-a-year-after-employee-forgets-login/" target="_blank"&gt;the state approved gun carry licence applications without carrying out background checks&lt;/A&gt;.&amp;nbsp; The reason? An employee couldn't remember her login for the check system.&amp;nbsp; So she just didn't check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am reminded of a situation where sales and marketing was supposed to carry out virus scans before they installed our product.&amp;nbsp; They had previously been using an inferior product and I mandated that they using a more accurate product.&amp;nbsp; At one point a machine was brought in as a problem.&amp;nbsp; First step in my process was to scan the machine, and, sure enough, it was infected.&lt;/P&gt;&lt;P&gt;"Did you scan it?"&lt;/P&gt;&lt;P&gt;"Yes."&lt;/P&gt;&lt;P&gt;"Did you use the right scanner?"&lt;/P&gt;&lt;P&gt;"Well, no, we used the old one."&lt;/P&gt;&lt;P&gt;"Why did you use the old scanner, when I've specified that you have to use the new one?"&lt;/P&gt;&lt;P&gt;"Well, when we use the one you told us to, it finds viruses ..."&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:49:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11486#M1107</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T08:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Background checks? We don' need no background checks ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11501#M1110</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Well, when we use the one you told us to, it finds viruses ..."&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes the peril of being a good security person. When you find threats and insecurities they like you, until you shutoff their USB ports, block auto forwarding of emails, etc.&lt;/P&gt;&lt;P&gt;Then you become "that" guy/gal.............&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 22:02:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11501#M1110</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2018-06-14T22:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Background checks? We don' need no background checks ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11532#M1122</link>
      <description>&lt;P&gt;Don't know what to say other than its always a good idea to scan with two distinctly different A/V engines. When I have Trend Micro installed I use F-Secure or Symantec or McAffee or whomever as a separate control. Your controls were bypassed because you made a suggestion not a policy from the get go. This needs to be a policy level argument otherwise your end-user simply made a excuse for you to choke. Well... someone is going to choke on this, might as well be the end-user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something similar happened to me here where I had someone bypass the A/V by deleting the .exe on a machine more than sufficiently protected from 3rd party media, booting or software load. No, my person injected code into the .exe to destroy it. Smart. So smart that I wrote a policy indicating my displeasure with circumventing security controls.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 21:37:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Background-checks-We-don-need-no-background-checks/m-p/11532#M1122</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-06-15T21:37:13Z</dc:date>
    </item>
  </channel>
</rss>

