<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Complex solutions as job security in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Complex-solutions-as-job-security/m-p/15195#M493</link>
    <description>&amp;gt; ro83 (Newcomer II) posted a new topic in Tech Talk on 10-03-2018 11:49 AM in the&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I have experienced situations where some people avoid learning new skills by&lt;BR /&gt;&amp;gt; producing complex code, configuration, business processes and/or documentation&lt;BR /&gt;&amp;gt; to secure their position in the company.&lt;BR /&gt;&lt;BR /&gt;Obscurity is not security. To put it another way, security by obscurity does not&lt;BR /&gt;work. Not in the long haul.&lt;BR /&gt;&lt;BR /&gt;(Some people may argue this point, but it is basically a generalization and offshoot&lt;BR /&gt;of Kerckhoff's Law.)&lt;BR /&gt;&lt;BR /&gt;(Use of complex solutions as a form of job security is not going to work, either.&lt;BR /&gt;Not in the long term ...)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Saddest part of it is that this&lt;BR /&gt;&amp;gt; mentality is often supported by mid-level managers because finding new people&lt;BR /&gt;&amp;gt; can be hard and implementing additional controls like effective code reviews,&lt;BR /&gt;&amp;gt; four eye principle etc. can be costly and time-consuming.&lt;BR /&gt;&lt;BR /&gt;Unfortunately, adherence to this type of principle ensures that the company has&lt;BR /&gt;more problems than simply security ...&lt;BR /&gt;&lt;BR /&gt;&amp;gt; What should be the&lt;BR /&gt;&amp;gt; best possible solutions to avoid potential negative impact to the company and&lt;BR /&gt;&amp;gt; colleagues in long term?&lt;BR /&gt;&lt;BR /&gt;They are doomed. With this type of mindset acceptable, I doubt there is much&lt;BR /&gt;your can do without a *lot* of time and a significant position of authority in the&lt;BR /&gt;organization.&lt;BR /&gt;&lt;BR /&gt;The best bet for *you* is to find a new company and colleagues ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Capitalism is the astounding belief that the most wickedest of&lt;BR /&gt;men will do the most wickedest of things for the greatest good of&lt;BR /&gt;everyone. - John Maynard Keynes&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
    <pubDate>Wed, 03 Oct 2018 17:35:00 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2018-10-03T17:35:00Z</dc:date>
    <item>
      <title>Complex solutions as job security</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Complex-solutions-as-job-security/m-p/15180#M492</link>
      <description>&lt;P&gt;I have experienced situations where some people avoid learning new skills by producing complex code, configuration, business processes and/or documentation to secure their position in the company. Saddest part of it is that this mentality is often supported by mid-level managers because finding new people can be hard and implementing additional controls like effective code reviews, four eye principle etc. can be costly and time-consuming. What should be the best possible solutions to avoid potential negative impact to the company and colleagues in long term?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 15:49:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Complex-solutions-as-job-security/m-p/15180#M492</guid>
      <dc:creator>ro83</dc:creator>
      <dc:date>2018-10-03T15:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Complex solutions as job security</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Complex-solutions-as-job-security/m-p/15195#M493</link>
      <description>&amp;gt; ro83 (Newcomer II) posted a new topic in Tech Talk on 10-03-2018 11:49 AM in the&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I have experienced situations where some people avoid learning new skills by&lt;BR /&gt;&amp;gt; producing complex code, configuration, business processes and/or documentation&lt;BR /&gt;&amp;gt; to secure their position in the company.&lt;BR /&gt;&lt;BR /&gt;Obscurity is not security. To put it another way, security by obscurity does not&lt;BR /&gt;work. Not in the long haul.&lt;BR /&gt;&lt;BR /&gt;(Some people may argue this point, but it is basically a generalization and offshoot&lt;BR /&gt;of Kerckhoff's Law.)&lt;BR /&gt;&lt;BR /&gt;(Use of complex solutions as a form of job security is not going to work, either.&lt;BR /&gt;Not in the long term ...)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Saddest part of it is that this&lt;BR /&gt;&amp;gt; mentality is often supported by mid-level managers because finding new people&lt;BR /&gt;&amp;gt; can be hard and implementing additional controls like effective code reviews,&lt;BR /&gt;&amp;gt; four eye principle etc. can be costly and time-consuming.&lt;BR /&gt;&lt;BR /&gt;Unfortunately, adherence to this type of principle ensures that the company has&lt;BR /&gt;more problems than simply security ...&lt;BR /&gt;&lt;BR /&gt;&amp;gt; What should be the&lt;BR /&gt;&amp;gt; best possible solutions to avoid potential negative impact to the company and&lt;BR /&gt;&amp;gt; colleagues in long term?&lt;BR /&gt;&lt;BR /&gt;They are doomed. With this type of mindset acceptable, I doubt there is much&lt;BR /&gt;your can do without a *lot* of time and a significant position of authority in the&lt;BR /&gt;organization.&lt;BR /&gt;&lt;BR /&gt;The best bet for *you* is to find a new company and colleagues ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Capitalism is the astounding belief that the most wickedest of&lt;BR /&gt;men will do the most wickedest of things for the greatest good of&lt;BR /&gt;everyone. - John Maynard Keynes&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 03 Oct 2018 17:35:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Complex-solutions-as-job-security/m-p/15195#M493</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-10-03T17:35:00Z</dc:date>
    </item>
  </channel>
</rss>

