<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shortage of Cyber Security Professionals ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22644#M2836</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1273539083"&gt;@j_M007&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;The 'chicken-and-the-egg conundrum!'&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Or is it the Cuckoo and the egg conundrum?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the newbies go read The Cuckoo's Egg by Cliff Stoll.&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2019 21:10:31 GMT</pubDate>
    <dc:creator>CISOScott</dc:creator>
    <dc:date>2019-05-21T21:10:31Z</dc:date>
    <item>
      <title>Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22628#M2826</link>
      <description>&lt;P&gt;Best bet for commodity futures?&amp;nbsp; Buy security professionals.&amp;nbsp; Apparently there is a world wide shortage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, right.&amp;nbsp; As I have noted elsewhere, and frequently, there's been a shortage my whole career.&amp;nbsp; I ain't rich yet.&amp;nbsp; There's a bit of a disconnect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OK, so first off, recently, there was Trump's "&lt;A href="https://community.isc2.org/t5/Industry-News/NEWS-Executive-Order-on-America-s-Cybersecurity-Workforce/m-p/21819" target="_blank" rel="noopener"&gt;executive order&lt;/A&gt;," which, &lt;A href="https://community.isc2.org/t5/Industry-News/NEWS-Executive-Order-on-America-s-Cybersecurity-Workforce/m-p/21831/highlight/true#M2687" target="_blank" rel="noopener"&gt;as I noted&lt;/A&gt;, is mostly about getting staff for (relatively low paying) government jobs, and probably isn't going to change much of anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, in Canada, &lt;A href="https://www.itworldcanada.com/article/industry-government-academics-form-group-to-help-solve-canadas-cyber-talent-shortage/418091" target="_blank" rel="noopener"&gt;another group has been formed&lt;/A&gt; "to craft a plan for cyber security education and workforce development."&amp;nbsp; Yeah, good luck with that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Returning to the US, the Marines are asking for &lt;A href="https://www.techspot.com/news/80111-us-marine-corps-seeks-volunteers-civil%20ian-cybersecurity-team.html" target="_blank" rel="noopener"&gt;civilian volunteers to make up a new computer task force cyber security unit&lt;/A&gt;.&amp;nbsp; According the the General responsible, "If anybody wants to join, you can sign up."&amp;nbsp; (Sounds a bit desperate, if you ask me ...)&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:12:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22628#M2826</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T09:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22634#M2827</link>
      <description>&lt;P&gt;A lot of us have been through the mill, yes, we were once young impressionable people, put into secure rooms, or indoctrinated with some form of military security regime, or discipline. &amp;nbsp; Given the current shortage, the key thing really is ensuring the correct ethics and skills and how to use them appropriately can be applied - this takes time. &amp;nbsp; Yes, I have seen situations whereby people with an aptitude have been made security analysts on the front desk - but they have been assisted with Augmented Intelligence and Machine Learning, to assist them to analyse new situations quickly and to make recommendations - but not to take away the decision making process at all. &amp;nbsp; People learn by mistakes, but the will they operate in the way, we expect under pressure?&amp;nbsp;&amp;nbsp; Will they know the difference between right and wrong or whether to conduct a vulnerability scan on a 10 Gigabit network segment without going gunho and then asking why things were breaking?&amp;nbsp; Or ensuring the correct authorisation is in place and the right parameters are set up before hitting the go button?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This needs some form of coaching, mentoring relationship to be created, to guide - or these new recruits could find themselves on the wrong side of the legislation, and not realising why?&amp;nbsp; Or the fact they find it more lucrative to move to the bad side, and make money on the Dark Web because they have the skills sets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets focus on the getting the new recruits, but at least ensuring they understand the ethics, and the level of trust required daily to conduct themselves in this business?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 19:41:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22634#M2827</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-05-21T19:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22636#M2829</link>
      <description>&lt;P&gt;Well, my experience tells me that the better statement is: There is a shortage of competent security leadership, and there is a shortage of competent IT leadership that &lt;U&gt;really&lt;/U&gt; recognizes the importance of security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once we solve these shortages, then we can actually say "there is a shortage of security professionals", or the shortage does not even exist ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 19:56:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22636#M2829</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2019-05-21T19:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22638#M2830</link>
      <description>&lt;P&gt;Perhaps there is another way to put this - all C level should be cyber security professionals, in order to run their businesses efficiently, effectively and keep them financially viable.&amp;nbsp; They are the key to understanding the level of Governance, Risk and Compliance that needs to be applied to maintain the health and welfare of their organisations.&amp;nbsp; They are ultimately responsible and can be struck off Directorship boards etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets start at the top,rather than the bottom?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/323397747"&gt;@Chuxing&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Well, my experience tells me that the better statement is: There is a shortage of competent security leadership, and there is a shortage of competent IT leadership that &lt;U&gt;really&lt;/U&gt; recognizes the importance of security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once we solve these shortages, then we can actually say "there is a shortage of security professionals", or the shortage does not even exist ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:01:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22638#M2830</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-05-21T20:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22639#M2831</link>
      <description>&lt;P&gt;The 'chicken-and-the-egg conundrum!'&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:00:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22639#M2831</guid>
      <dc:creator>j_M007</dc:creator>
      <dc:date>2019-05-21T20:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22640#M2832</link>
      <description>&lt;P&gt;Keep hearing there is a shortage, but I apply for positions that I don't get call backs on, and no one is making job offers to me.&amp;nbsp; Plus, I know of others struggling to find work while the "skill gap/shortage" is being pushed and people are being encouraged to take training, get certified, and get well paid jobs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I do see are jobs that have unrealistic requirements, that more fit someone with the skills/knowledge/experiences of 3 people.&amp;nbsp; Then you have recruiters and even hiring managers who don't seem to understand infosec, so reach out to people for jobs that aren't a good fit for them, or turn people away for silly reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(ex: I spent time trying to explain to a recruiter that an information security manager is not the same as an information security project manager.&amp;nbsp; Sigh.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think its more that the hiring process is broken, and no one seems interested in fixing it.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:05:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22640#M2832</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-05-21T20:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22641#M2833</link>
      <description>&lt;P&gt;I believe there is sufficient legislation to protect organisations, if only the C level acted responsibly, and acted accordingly?&amp;nbsp;&amp;nbsp; But the courts can only move so far or react within certain time spans, once sufficient evidence is gathered to commit a case.&amp;nbsp; The Chicken evolved like man over time, probably from the same amebic bacteria or derivative, according to the universal chemical rule book.&amp;nbsp;&amp;nbsp; However, often through many vices, cause mankind to evolve into all sorts of monsters, in the hope the less they do, will not affect their immediate chances of becoming famous possibly in the wrong way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:06:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22641#M2833</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-05-21T20:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22642#M2834</link>
      <description>&lt;P&gt;Perhaps the recruiter should be re-trained or we need to do due diligence to ensure the recruiter is in fact themselves credible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Keep hearing there is a shortage, but I apply for positions that I don't get call backs on, and no one is making job offers to me.&amp;nbsp; Plus, I know of others struggling to find work while the "skill gap/shortage" is being pushed and people are being encouraged to take training, get certified, and get well paid jobs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I do see are jobs that have unrealistic requirements, that more fit someone with the skills/knowledge/experiences of 3 people.&amp;nbsp; Then you have recruiters and even hiring managers who don't seem to understand infosec, so reach out to people for jobs that aren't a good fit for them, or turn people away for silly reasons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(ex: I spent time trying to explain to a recruiter that an information security manager is not the same as an information security project manager.&amp;nbsp; Sigh.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think its more that the hiring process is broken, and no one seems interested in fixing it.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:07:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22642#M2834</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-05-21T20:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22643#M2835</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;what you experienced is again IMHO the lack of competent leadership who really doesn't understand what the security needs are, but instead, cut and paste a bunch nonsense and load them on the poor recruiter / hiring manager.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp; You are absolutely right on the CxOs roles. As a matter of fact, the latest COBIT and ITIL all have recognized this, and have started incorporate best practices of security up to the executive / governance levels. It is no longer just a management / operation issue, and must be addresses at governance level.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:22:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22643#M2835</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2019-05-21T20:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22644#M2836</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1273539083"&gt;@j_M007&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;The 'chicken-and-the-egg conundrum!'&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Or is it the Cuckoo and the egg conundrum?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the newbies go read The Cuckoo's Egg by Cliff Stoll.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 21:10:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22644#M2836</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2019-05-21T21:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22645#M2837</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1602421967"&gt;@CISOScott&lt;/a&gt;Grab yourself a copy of the book or Kindle, and keep it on the bookshelf.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 21:25:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22645#M2837</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-05-21T21:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22660#M2841</link>
      <description>&lt;P&gt;Back when I was a Software Engineer, there was a shortage of those, but that didn't translate into high salary or job security or lots of opportunities due to the scarity.&amp;nbsp; So the fields may simply not have been as attractive as working in Finance, Law or Medicine.&amp;nbsp; It was seen as poor relation to more established fields in terms of pay and status.&amp;nbsp; I suspect InfoSec has a similar image problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back in 2013 at the ISC2 meeting at Warwick University there was a show of hand for women in InfoSec, people under 30, under 40, under 50 and so on.&amp;nbsp; The majority of the audience/membership were white, males in their 40s and 50s.&amp;nbsp; So there is a lack of diversity and aging profession, which is in itself a problem.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 10:46:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22660#M2841</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-05-22T10:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22662#M2842</link>
      <description>&lt;P&gt;There is often no clear understanding of the different roles and skill sets in InfoSec, so many organisations simply ask for almost everything for every role.&amp;nbsp; It's not too uncommon to find policies, standards development, SETA, compliance, PCI, security architecture, security audits, administering security tooling, forensics, pen testing and incident response all in the same job ad.&amp;nbsp; Whilst experiences in InfoSec can be diverse, very few people have years of experience every single aspect of InfoSec.&amp;nbsp; So perfectly capable candidates get rejected, rather than consider candidates who are a 70% fit, and it limits mobility in the labour market, so even if in InfoSec already staff get stuck in roles and not developed.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 11:04:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22662#M2842</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-05-22T11:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22673#M2843</link>
      <description>&lt;P&gt;So many fowl problems occur when we bury our head in the sand!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cbc.ca/news/canada/british-columbia/peacock-nuisance-animals-beauty-beast-1.4649532" target="_blank"&gt;https://www.cbc.ca/news/canada/british-columbia/peacock-nuisance-animals-beauty-beast-1.4649532&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 14:32:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22673#M2843</guid>
      <dc:creator>j_M007</dc:creator>
      <dc:date>2019-05-22T14:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22674#M2844</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/783051913"&gt;@Steve-Wilme&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;There is often no clear understanding of the different roles and skill sets in InfoSec, so many organisations simply ask for almost everything for every role.&amp;nbsp; It's not too uncommon to find policies, standards development, SETA, compliance, PCI, security architecture, security audits, administering security tooling, forensics, pen testing and incident response all in the same job ad.&amp;nbsp; Whilst experiences in InfoSec can be diverse, very few people have years of experience every single aspect of InfoSec.&amp;nbsp; So perfectly capable candidates get rejected, rather than consider candidates who are a 70% fit, and it limits mobility in the labour market, so even if in InfoSec already staff get stuck in roles and not developed.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hence why you have work with the NICE framework to establish more clearly job roles/duties.&amp;nbsp; Otherwise we get the nonsense of companies saying they want an "Information Security Officer" when what they really want is an Analyst or Engineer (yeah, seen that...).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had heard something recently that in IT (and to extension infosec) that often times people have more and more dumped on their plate, sometimes stuff that maybe they shouldn't be responsible for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then those people quit, and their company is left scrambling to fill that role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have to wonder if some of these ridiculous job descriptions are due to this?&amp;nbsp; They are trying to fill a role that had a lot of stuff dumped on them, and they think they can find someone with the same skills/experience to fill the role.&amp;nbsp; Sadly, of course, they quest for someone to "hit the ground running" and do all those things makes that a losing proposition.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 14:41:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22674#M2844</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-05-22T14:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22677#M2846</link>
      <description>&lt;P&gt;Yes quite possibly; it's often sink or swim.&amp;nbsp; The dumped on employee is seen as more capable and 'passionate', so gets more and more given to them over time.&amp;nbsp; If you want something doing give it to someone who's already very busy.&amp;nbsp; And you know where this can lead; to burn out and unexpected resignations.&amp;nbsp; Only then is it realised that there was a 'key man' dependency and the organisation looks for someone else to take on the lot, usually without sufficient budget and without authority within the organisation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 14:55:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22677#M2846</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-05-22T14:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22686#M2848</link>
      <description>&amp;gt; j_M007 (Community Champion) posted a new reply in Industry News on 05-22-2019&lt;BR /&gt;&lt;BR /&gt;&amp;gt; So many fowl problems occur when we bury our head in the sand! &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I think you're thnking of ostriches, not peacocks.&lt;BR /&gt;&lt;BR /&gt;But, yes, you're right. Peacocks can be a nuisance, but only if not controlled&lt;BR /&gt;properly. They seem to be able to thrive just about anywhere and always seem to&lt;BR /&gt;get into trouble (at Royal Roads they killed off a set of pollarded trees that had&lt;BR /&gt;been around for decades), but it's hard to call them an invasive species because&lt;BR /&gt;they *can* be controlled if only you take the proper action.&lt;BR /&gt;&lt;BR /&gt;A good example of a risk management problem ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Of all things, good sense is the most fairly distributed:&lt;BR /&gt;everyone thinks he is so well supplied with it that even those&lt;BR /&gt;who are the hardest to satisfy in every other respect never&lt;BR /&gt;desire more of it than they already have.&lt;BR /&gt;- Rene Descartes (1596-1650), Discours de la Methode (1637)&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 22 May 2019 17:32:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22686#M2848</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-05-22T17:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22703#M2851</link>
      <description>&lt;P&gt;I'm glad you caught the mixed meta force my fine feathered friend. An eagle-eyed kiwi found tracks of a many-splendored bird of another feather. I reckon the mega bird would have made a mega mess. Not unlike some of the turkeys we have seen hereabouts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.vice.com/en_us/article/zmpm7y/new-zealand-man-goes-swimming-finds-footprints-of-extinct-mega-bird" target="_blank"&gt;https://www.vice.com/en_us/article/zmpm7y/new-zealand-man-goes-swimming-finds-footprints-of-extinct-mega-bird&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 19:49:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22703#M2851</guid>
      <dc:creator>j_M007</dc:creator>
      <dc:date>2019-05-22T19:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22704#M2852</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1273539083"&gt;@j_M007&lt;/a&gt;Yes indeed - the Wellington Museum was not amused, as University of Otago, followed it up and they missed out on the find.&amp;nbsp;&amp;nbsp; Indeed, mixed metaphors - lets hope we do not end up extinct like the "Moa".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/Moa" target="_blank"&gt;https://en.wikipedia.org/wiki/Moa&lt;/A&gt;, Unfortunately the colonists f(Polynesians) found them tasty and caused their demise very quickly in 1280 on wards.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 20:18:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22704#M2852</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-05-22T20:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Shortage of Cyber Security Professionals ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22710#M2854</link>
      <description>&lt;P&gt;From birds to songbirds .... Moa moa moa, how do you like it?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=RlJGrIyt-X8" target="_blank"&gt;https://www.youtube.com/watch?v=RlJGrIyt-X8&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 20:56:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shortage-of-Cyber-Security-Professionals/m-p/22710#M2854</guid>
      <dc:creator>j_M007</dc:creator>
      <dc:date>2019-05-22T20:56:31Z</dc:date>
    </item>
  </channel>
</rss>

