Skip to main content

Security Software and the Cowboy pants

Starting to feel a sense of frustration. No it doesn't effect me personally. I am still the same 'white hat' as always.
I went through the series of interviews for different positions recently. It was an absolute waste of time. What caught my attention is a level of arrogance and mindless stupidity coming from the people who should be paying attention. Each interview was along same well travelled paths:
Can you install software?
Can you connect it to the ERP (or whatever they connecting it to) ?
etc.
So they all concentrate on the Functional requirements. Most forget the security of your software falls into the Non-Functional requirements.
No one had a slightest idea that before you implement Functional requirements you need to make sure that your 'Security Software' being it Sailpoint, Oracle or Forgerock or whatever:
is in itself secured.
The buzz word 'security software' doesn't make it to be secure on its own.
Someone has to do it.
Otherwise your Security Software will be looking like a cowboy wearing pants with two guns in the front pockets and two wide cutaways in the back.



Yes your company rear will be exposed.
Almost all of the vendors use 3 tiered system:
Front web tier
Application tier
Database Tier
If none of these tiers are hardened and secured you will end up with the pants above.
Any IAM implementation project therefore need to start and concentrate on fulfilling the Non-Functional requirements first and foremost.
Only after the Non-Functional requirements are tested and approved the Functional requirements can be addressed.
I strongly recommend to follow NIST, ASD and some other standards to secure the 'Security Software'.

But you can always buy pants as they are widely available out there :) and plenty of integrators who are happy to sell them.

Comments

Popular posts from this blog

Artificial I

Yes not misspelled and my title is right: Artificial I . Lets us zoom for a second on 'why' and 'what' and then we can have a look at 'when'. Why ? Look at yourself in the mirror for 1 min. until you have your image in your memory. (Warning: to some the experience may be to much to take. I am not joking or alluding to anything here. Simply stating the fact that this process is deeply personal and may evoke number of complex emotions. Some of them may be not as pleasant as you would expect it.) Then sit yourself somewhere comfortably and close your eyes. Concentrate and try to bring your image back. You may succeed or you may not. It all depends on your brain ability to recall the images quickly and reliably over time as well as strange desire and ability to forget certain images. Now you probably slowly starting to realize by yourself is 'why' :) We need some sort of third party involvement here to help us along way as we have our limitations

White Hat

Was talking to my friend 'White Hat' He is still hopefull and optimistic. Alone as everyone left to the BlackHat he still picking at his bugs and whatever he can find there. Will he be able to deliver on the promise and save us from Darth forces? I hope he will.

Linus hasn’t received any recommendations yet.

I find it extremely interesting that Linus Torvalds Linkedin profile doesn't have any 'Recommendations: Received (0) Given (1) Linus hasn’t received any recommendations yet.' You may say he doesn't need it. Everyone knows he invented Linux. Well almost everyone :) But it also shows and reflects the world we are living. You barely hear his name and he is not in the news. I know people with 10, 100 recommendations. It is all about building and maintaing your connections. So the old saying goes: "Its not what you know, its who you know" It works amazingly well even nowadays in the age of knowledge. I think of the Linus legacy and I think of: Security and stability Extensibility and simplicity I think of Bill Gates legacy and I think of: Unsecure and untrustworthy Proprietory and complex One is humble and down to earth creator The other is shrewd and cunning businessman One is doing OK The other is billionaire You can now run Linux on Windo