<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bad Penny</title>
	<atom:link href="http://gorrie.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://gorrie.org</link>
	<description>bound to turn up.  The adventures of an early adopter.</description>
	<lastBuildDate>Sat, 27 Feb 2010 23:44:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Public and Private</title>
		<link>http://gorrie.org/2010/02/22/the-social-periphery/</link>
		<comments>http://gorrie.org/2010/02/22/the-social-periphery/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 00:26:47 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
				<category><![CDATA[Biographical]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://gorrie.org/?p=742</guid>
		<description><![CDATA[<p>In this brave new internet world (as of about 1995), I&#8217;ve been thinking of my personal information sharing generally as public and private.</p>
<p>Information Classification</p>
<p>Because of my work, classifying information comes as second nature. I have two separate and non-intersecting information streams. You are reading part of one of them.</p>
<p>100% of the talk about people on [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://gorrie.org/blog/../uploads/2010/02/social-network_illu_farbig.jpg"><img class="alignleft size-medium wp-image-743" title="social-network_illu_farbig" src="http://gorrie.org/blog/../uploads/2010/02/social-network_illu_farbig-300x179.jpg" alt="" width="300" height="179" /></a>In this brave new internet world (as of about 1995), I&#8217;ve been thinking of my personal information sharing generally as public and private.</p>
<p><strong>Information Classification</strong></p>
<p>Because of my work, classifying information comes as second nature. I have two separate and non-intersecting information streams. You are reading part of one of them.</p>
<p>100% of the talk about people on social networks and things going horribly wrong are people who don&#8217;t make clear distinctions between the public, professional, personal, and social aspect of their lives. <a href="http://au.news.yahoo.com/a/-/technology/6839603/modern-etiquette-how-to-decline-facebook-friends-without-offence/">Getting into etiquette with social networks</a> can be tricky. I find it best to, as a rule, separate business and pleasure.</p>
<p><strong>Partial Disclosure</strong></p>
<p>Public information is available for anyone in the world to read. I put it out there so that people can learn a bit about me.</p>
<p>The reason I started writing things in the public eye is because I realized that if I didn&#8217;t define myself and give people something to read who didn&#8217;t know me, someone else would. This is the same reason that I don&#8217;t publish raw slide decks of my presentations, but I put my speaking points intermixed with the slides in a blog posting. Text based communication loses a lot of intent and inflection, so I try to make up for it in this way.</p>
<p>I didn&#8217;t want to have a blog. Once upon a time, when I was younger (and even more naive), I thought that I could get by on merit alone; I believed that if I did good work, my work would be recognised for and stand on its merits. I read things like <a href="http://en.wikipedia.org/wiki/The_Fountainhead_%28film%29">The Fountainhead</a> (watch the movie) and took from it &#8220;Oh! If I do good work and work toward my own sense of excellence, I will triumph in the end!&#8221;</p>
<p>I don&#8217;t think so anymore.  I think success takes more than merit.</p>
<p>Not only do you have to do good work, but people need to know about it. You need to help people directly, impart lessons you&#8217;ve learned without being an arrogant jerk, and sell them on why a good solution is better than a thought-to-be-suffient solution.</p>
<p><strong>Blogging</strong></p>
<p>When <a href="http://www.livejournal.com/">Livejournal</a> came out, I thought that this was lame in the same way <a href="http://en.wikipedia.org/wiki/Jennifer_Ringley">Jennicam</a> was lame. My conclusion was that blogging was about media and <a href="http://www.urbandictionary.com/define.php?term=attention%20whores">attention seeking</a>. I didn&#8217;t have a need to have a public blog for people who didn&#8217;t know me could learn tons about me without my knowing them.</p>
<p>More importantly, it wasn&#8217;t interesting.</p>
<p>I found it massively egotistical that anyone would want to know what I bought at the grocery store or ate for lunch. I didn&#8217;t understand sharing of the mundane. Clearly many people do not share this opinion today.</p>
<p><a href="http://en.wikipedia.org/wiki/Ranulph_Fiennes"><img class="alignleft size-full wp-image-744" title="Ranulph-Fiennes-book-cover-232x300" src="http://gorrie.org/blog/../uploads/2010/02/Ranulph-Fiennes-book-cover-232x300.jpg" alt="" /></a>The stuff I put on my blog are my presentations, the way I manipulate data for my own uses when I haven&#8217;t seen it represented in my way previously, or my attempts to explain the poorly explained. The ideal that I aspire to is &#8220;I wouldn&#8217;t find it interesting to read, I don&#8217;t write it.&#8221; I imagine that might come off as rampagingly egotistical at times, but I really make an effort not to be. I laugh at myself and at life as much as possible. It&#8217;s pretty ridiculous a lot of the time. My work tends to be very serious and can effect, in a real appreciable way, the lives of others. I take it very seriously. When people do important work badly, I can take it as a personal affront.</p>
<p>I would like to post more, but too much of it is sensitive, under contractual obligations, or in personal confidence. Unlike many people that do not share my views, I can&#8217;t disclose in good faith.</p>
<p><strong>Social networks</strong></p>
<p>What I find interesting about social networks, and by that I mean mostly <a href="http://twitter.com/gorrie">Twitter</a> and Facebook, is that it can introduce a gray area between public and private information; <strong>a social periphery</strong> of information that busy people share in order to keep in touch with people they think are cool.</p>
<p>That&#8217;s pretty much how I view a friends list; &#8220;These are people I think are cool.&#8221; If I would invite you to an informal party is my general baseline for inclusion into my social network.</p>
<p><a href="http://twitter.com/gorrie">Twitter</a>: Low attention span blogging and random link sharing.</p>
<p><a href="http://gorrie.org/">Bad Penny</a>: Informal writings, past sharable presentations, and general information sharing of things I find interesting.</p>
<p>Facebook: Fun people that I associate with socially.</p>
<p><a href="http://linkedin.com/in/gorrie">LinkedIn</a>: People I have done business with or know professionally that I would vouch for. Yes. I really do know all of those people and have had dealings in the past.</p>
<p><strong>Be Cool</strong></p>
<p>As any good rule, it is proven by its exceptions. Excessively cool people are allowed to break most rules.</p>
<p>My advice to everyone: be excessively cool and don&#8217;t take things seriously that do not merit being taken seriously.</p>
<blockquote><p>Life is too short to be taken seriously. &#8212; Oscar Wilde</p>
<p>Work and play are words used to describe the same thing under differing conditions. &#8211;Mark Twain</p>
<p>In every real man a child is hidden that wants to play. &#8211;Friedrich Nietzsche</p>
<p>Humanity has advanced, when it has advanced, not because it has been sober, responsible, and cautious, but because it has been playful, rebellious, and immature. &#8211;Tom Robbins</p>
<p>Necessity may be the mother of invention, but play is certainly the father. &#8211;Roger von Oech</p></blockquote>
<img src="http://gorrie.org/blog/wp-content/plugins/pixelstats/trackingpixel.php?post_id=742&amp;ts=1268981977" style="display:none;" alt="pixelstats trackingpixel"/>

<p>Related posts:<ol><li><a href='http://gorrie.org/2008/03/19/new-facebook-private-features/' rel='bookmark' title='Permanent Link: New Facebook private features'>New Facebook private features</a></li>
<li><a href='http://gorrie.org/2010/01/20/new-nettiqute/' rel='bookmark' title='Permanent Link: New Nettiqute: A simple guide to communicating with your favorite geeks.'>New Nettiqute: A simple guide to communicating with your favorite geeks.</a></li>
<li><a href='http://gorrie.org/2009/08/29/social-networks/' rel='bookmark' title='Permanent Link: I judge you: A social networks commentary'>I judge you: A social networks commentary</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2010/02/22/the-social-periphery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monopoly Customer Service</title>
		<link>http://gorrie.org/2010/02/12/monopoly-customer-service/</link>
		<comments>http://gorrie.org/2010/02/12/monopoly-customer-service/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 21:45:17 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[agile]]></category>
		<category><![CDATA[comcast]]></category>
		<category><![CDATA[culture]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://gorrie.org/?p=732</guid>
		<description><![CDATA[<p>After a few years of avoiding the cable industry, I went ahead and signed up for Comcast Highspeed2Go, a new bundled service where they resell Clearwire and combine it with conventional broadband home internet service.</p>
<p>As per usual large non-technical business operations, and I feel that I must classify Comcast as such, they launched a product [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://gorrie.org/blog/../uploads/2010/02/394.jpg"><img class="alignleft" src="http://gorrie.org/blog/../uploads/2010/02/394-tm.jpg" alt="394.jpg" width="300" height="200" /></a>After a few years of avoiding the cable industry, I went ahead and signed up for Comcast <a href="http://www.comcast.com/highspeed2Go/">Highspeed2Go</a>, a new bundled service where they <a href="http://www.fiercewireless.com/story/comcast-resell-clearwire-wimax-service-portland/2009-03-17">resell Clearwire</a> and combine it with conventional <a href="http://en.wikipedia.org/wiki/Broadband">broadband</a> home internet service.</p>
<p>As per usual large non-technical business operations, and I feel that I must classify Comcast as such, they launched a product that they could not support. I spent a few hours on the phone with them attempting to figure out why they disabled wireless cards they sent me. They sent me a total of three cards and then disabled each of them after about a week.</p>
<p>This last week I didn&#8217;t feel like giving Comcast another two hour free tech support call and sent all of their wireless gear back to them. Previously I spent a few hours talking to people in attempts to navigate their broken process in order to get home service installed and activated.</p>
<p>The time of a consumer seems to be a free resource according to Comcast. They have a <a href="http://code.google.com/p/robodialer/">robodialer</a> calling me now asking me to call some number. No thanks. I&#8217;m already at my quota for time wasted talking to you guys this month. I&#8217;ll be happy to pay you when you send me a bill consistent with our agreements.</p>
<p>This is nothing new. Back when I managed <a href="http://en.wikipedia.org/wiki/Leased_line">leased lines</a> from <a href="http://en.wikipedia.org/wiki/Telephone_company">telcos</a>, I eventually found a backchannel into their top tier of support to get recurring and completely preventable problems resolved. I monitored their uptime. I reported their outages. I gave them their remediation process. If I didn&#8217;t, the business that I worked for would suffer.</p>
<p>Usually I assume good will, but my experiences as a consumer and as a professional with Comcast in particular point in another direction.</p>
<p>My point here is that branding is considered more substantial than service. I&#8217;m sure this is a business decision that was made when they worked the numbers and determined that giving five 9s of uptime and quick problem resolution <a href="http://app.businessweek.com/UserComments/get_reviews;jsessionid=503F7A337767B6B5FCA2B69D104E8B6A?action=all&amp;productId=21232&amp;style=wide">was more expensive</a> than just running more commercials, forcing out competition, <a href="http://arstechnica.com/tech-policy/news/2010/01/municipal-fiber-needs-more-fdr-localism-fewer-state-bans.ars">suing municipal projects</a> designed to give an alternative, and having <a href="http://www.google.com/search?q=comcast+twitter&amp;hl=en&amp;rls=en&amp;tbs=mbl:1&amp;tbo=u&amp;ei=47t1S4SSHZWINsjnuZcP&amp;sa=X&amp;oi=realtime_result_group_more_results_link&amp;ct=title&amp;resnum=1&amp;ved=0CA8Q5QUwAA">the illusion of support on Twitter</a>.</p>
<p><a href="http://gorrie.org/blog/../uploads/2010/02/amoeba21.jpg"><img class="alignleft" src="http://gorrie.org/blog/../uploads/2010/02/amoeba21-tm.jpg" alt="amoeba21.jpg" width="266" height="177" /></a>In an upcoming white paper, some associates and I will be discussing some aspects of this issue. Sometimes quality of service and streamlined operational works matter. Occasionally a company makes a business case for giving good service and honest commitments. Invariably, they are purchased and wrapped under one of the huge brands to be forgotten after their customers are re-absorbed into the amoeba of near-monopoly mediocrity.</p>
<p>This seems to be the new model for innovators and people who are good at their jobs:</p>
<ul>
<li>Find an unmet market need to improve</li>
<li>Do it better, faster, more reliably, or with pretty colors</li>
<li>Get bought out and paid (mostly) in stock</li>
<li>See your business die at the hands of the insiders that can&#8217;t improve themselves</li>
<li>Move on to something else</li>
</ul>
<p>Where does this leave the market? Large non-agile organizations who are prone to mismanagement buy all of the <a href="http://en.wikipedia.org/wiki/Intellectual_property">intellectual property</a> and use <a href="http://en.wikipedia.org/wiki/Lobbying">political influence</a> and <a href="http://www.justice.gov/atr/public/guidelines/primer-ncu.htm">bare-knuckle market pressures</a> to keep themselves on top of the heap.</p>
<p>Result: the market and consumers suffer.</p>
<p>See also the current state of <a href="http://en.wikipedia.org/wiki/Patent">patents</a>, <a href="http://en.wikipedia.org/wiki/Software_patent_debate">software</a> and <a href="http://archives.cnn.com/2000/TECH/computing/04/12/patent.squatter.idg/">otherwise</a>.</p>
<p>Some services and systems should not be held to the minimum standard of MBA business sufficiency where any excess money spent past the point where the customer will not fire the vendor is waste. My experience tells me that the standard of <a href="http://en.wikipedia.org/wiki/High_availability">five 9s</a> is generally becoming a thing of the past. Huge websites turn themselves off for multi-hour maintenance routinely with no notice. Cell phone providers incur day-long nationwide outages. Cable companies turn down a variety of services without warning or notification for undetermined amounts of time.</p>
<p>No standard of service seems to be the preeminent emerging standard of service. The <a href="http://www.allonhill.com/blog/myth-of-disposable-worker">myth of the disposable worker</a> is in full effect here.</p>
<p>I&#8217;m seeing this as a market opportunity for service providers. I would wager that consumers who can pay will pay to not talk to these people. That was the <a href="http://speakeasy.net/">Speakeasy</a> sales model when I was their consumer in the past:</p>
<blockquote><p>We&#8217;ll provide you with DSL service and you won&#8217;t have to talk to any incompetent jerks. Pay a little more a month and it&#8217;s completely worth it.</p></blockquote>
<p><a href="http://gorrie.org/blog/../uploads/2010/02/toast.jpg"><img class="alignleft" src="http://gorrie.org/blog/../uploads/2010/02/toast-tm.jpg" alt="toast.jpg" width="211" height="200" /></a><a href="http://www.dslreports.com/reviews/93">Speakeasy</a> could compete with <a href="http://www.dslreports.com/comments/1711">Covad</a> and <a href="http://www.dslreports.com/reviews/872">Qwest</a> offerings (even though they resell the both of them) because the big guys do such a bad job of taking care of their customers. Qwest and Covad are on board with this Comcast consumer model.</p>
<p>These MITMing businesses should increase as this continues since real competition is <a href="http://money.cnn.com/2005/06/27/technology/broadband_ruling/index.htm">not currently allowed to occur</a> simply because consumer time does have a value that is not being addressed.</p>
<p>The cable and other telcos had better watch out that they don&#8217;t <a href="http://money.cnn.com/2010/01/06/news/companies/cable_bill_cost_increase/index.htm">kill their own markets</a>. As soon as a fast data alternative comes along, be it from <a href="http://googleblog.blogspot.com/2010/02/think-big-with-gig-our-experimental.html">Google</a>, a <a href="http://www.broadband.gov/">national broadband plan</a>, or <a href="http://searchtelecom.techtarget.com/news/article/0,289142,sid103_gci1378874,00.html">fast unlimited wireless</a>, all of their business models are toast.</p>
<p>Keep it up, guys. We&#8217;ll see you in the technology deadpool soon enough.</p>
<img src="http://gorrie.org/blog/wp-content/plugins/pixelstats/trackingpixel.php?post_id=732&amp;ts=1268981977" style="display:none;" alt="pixelstats trackingpixel"/>

<p>Related posts:<ol><li><a href='http://gorrie.org/2009/12/20/comcast-wimax/' rel='bookmark' title='Permanent Link: Comcast Wimax'>Comcast Wimax</a></li>
<li><a href='http://gorrie.org/2007/11/02/phone-followup-again/' rel='bookmark' title='Permanent Link: Phone followup (again)'>Phone followup (again)</a></li>
<li><a href='http://gorrie.org/2007/04/23/bbb-complaint-vonage/' rel='bookmark' title='Permanent Link: BBB complaint:  Vonage'>BBB complaint:  Vonage</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2010/02/12/monopoly-customer-service/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Politics of Respect</title>
		<link>http://gorrie.org/2010/02/12/the-politics-of-respect/</link>
		<comments>http://gorrie.org/2010/02/12/the-politics-of-respect/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 16:00:00 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[culture]]></category>

		<guid isPermaLink="false">http://gorrie.org/?p=717</guid>
		<description><![CDATA[<p> There is a lot of perennial talk of social engineering and direct project/resource management. Attempts to solve complicated political situations with manipulation or a slick widget tend not to work very well over time. They are not addressing the underlying issue.</p>
<p>The wedge of compliance or a mandate from a framework may get some base [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://gorrie.org/blog/../uploads/2010/02/201002111719.jpg"><img class="alignleft" src="http://gorrie.org/blog/../uploads/2010/02/201002111719-tm.jpg" alt="201002111719.jpg" width="266" height="283" /></a> There is a lot of perennial talk of social engineering and direct project/resource management. Attempts to solve complicated political situations with manipulation or a slick widget tend not to work very well over time. They are not addressing the underlying issue.</p>
<p>The wedge of compliance or a mandate from a framework may get some base requirements moving. However, in order to get people; chief executives and influential management, towing the line for a healthy risk and security governance program, it will take something more. It takes a bidirectional respect for the people involved and bringing the conversation to them in terms that they, your audience, understands.</p>
<p>In short, technology risk in general is not well understood by many practitioners. Outside of direct practitioners it is barely understood at all. Technology risks to business can be so complicated to understand that it needs to be interpreted and put into well understood terms that everyone understands, such as dollars.</p>
<p>Fostering a climate of respect and reward of long term goals instead of a short-term win is key to the success of any real life security governance program.</p>
<p>I have some thoughts on how to begin.</p>
<p><span style="text-decoration: underline;">Respect your audience:</span></p>
<ul>
<li>Present in terms they understand.</li>
<li>To foster long term success, win by soft persuasion to the right path and finding of common goals. Not with a compliance beatdown or audit hammer.</li>
</ul>
<p><span style="text-decoration: underline;">Respect peoples time:</span></p>
<ul>
<li>Have an agenda for your meetings and stick to it. Get through your agenda, keep it focused, and conclude your meetings quickly. Make effective use of everyones time.</li>
<li>Focus your presentations. Have the subject matter you are presenting be relevant and interesting to your audience. &#8220;If your numbers are boring, then you&#8217;ve got the wrong numbers&#8221; said the esteemed <a href="http://en.wikipedia.org/wiki/Edward_Tufte">Edward Tufte</a>. Keep in mind his <a href="http://en.wikipedia.org/wiki/Edward_Tufte#Criticism_of_PowerPoint">criticism of PowerPoint</a>.</li>
<li>Realize that you must effectively communicate organization needs and concerns in a language and context so that it is understood. This will enable the organization, and individuals, to form a measured and concise response.</li>
</ul>
<p><a href="http://gorrie.org/blog/../uploads/2010/02/201002111703.jpg"><img class="alignleft" src="http://gorrie.org/blog/../uploads/2010/02/201002111703-tm.jpg" alt="201002111703.jpg" width="266" height="200" /></a></p>
<p><span style="text-decoration: underline;">Respect your resources:</span></p>
<ul>
<li style="list-style-type: none; list-style-position: initial; list-style-image: initial;"></li>
<li>Project management often overtasks. Assume and extol good will and respect and express it to those with whom you work. When performed correctly, you should find a net productivity gain. This is especially true with your indirect reports. <a href="http://en.wikipedia.org/wiki/Trust,_but_verify">Trust but verify, comrade</a>!</li>
<li>Slow down your initial reaction to assign blame when priorities collide. Make a measured response that will be constructive to your resource, manager, executive, or business partner. Enter the conversation with <em>at</em> <em>least the appearance</em> of malleability and an open mind. The respect of at least entertaining the feedback, advice, and input of others into the decision making process earns good will and political capital.</li>
</ul>
<p><span style="text-decoration: underline;">Respect the constraints of your organization:</span></p>
<ul>
<li>I can&#8217;t tell you the number of encounters I have had with peers who understand the role of a security engineer but do not understand risk management. An information security professional is <em>very rarely</em> tasked with eliminating all risks inherent in a system. Most often it is reducing risk and exposure to amounts that are acceptable to the organization for a cost they can tolerate. The biggest challenge that an information security professional has is communicating in relevant terms the unmitigated risks and exposures to the organization they are working within. <strong>Don&#8217;t take it personally</strong> when the perfect ideal is not made a reality. Optimize, compartmentalize, and reduce exposure. Getting this fit right is done by putting risk in terms everyone can understand, maturing an organization, and identifying exposures at an early stage of development.</li>
<li>Because of the vast differences in organizations, there is almost never a silver bullet solution to risk. Everything must be right-sized both at the design table and where the rubber meets the road. Often timetables for change will be longer than desired. The important part is that change is happening. The schedule can change as the landscape, challenges, and risks change.</li>
</ul>
<p>Too often I hear other fellows in the trade using harsh words to begrudge people who do not understand risk management instead of lamenting their inability to express it in terms that they will understand. Too often problems arise in not communicating effectively and in not earning or giving respect. This failure in communication was what I read into this CSO Online article about <a href="http://www.csoonline.com/article/537463/">a $10M raise in budget after a showboaty penetration report</a>.</p>
<p>Ira says &#8220;grab by the balls.&#8221; I say &#8220;communicate effectively and with respect.&#8221;</p>
<img src="http://gorrie.org/blog/wp-content/plugins/pixelstats/trackingpixel.php?post_id=717&amp;ts=1268981977" style="display:none;" alt="pixelstats trackingpixel"/>

<p>Related posts:<ol><li><a href='http://gorrie.org/2007/12/19/politics-in-system-security/' rel='bookmark' title='Permanent Link: Politics in system security'>Politics in system security</a></li>
<li><a href='http://gorrie.org/2009/07/16/toorcamp/' rel='bookmark' title='Permanent Link: The Trials of Toorcamp'>The Trials of Toorcamp</a></li>
<li><a href='http://gorrie.org/2007/11/12/itci-2007/' rel='bookmark' title='Permanent Link: ITCi 2007'>ITCi 2007</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2010/02/12/the-politics-of-respect/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Specialists, Generalists, Incompetence, and Cognitive Bias</title>
		<link>http://gorrie.org/2010/01/24/generalists/</link>
		<comments>http://gorrie.org/2010/01/24/generalists/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 15:45:03 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[discussion]]></category>
		<category><![CDATA[expert]]></category>
		<category><![CDATA[generalis]]></category>
		<category><![CDATA[specialist]]></category>

		<guid isPermaLink="false">http://gorrie.org/?p=694</guid>
		<description><![CDATA[<p>I wanted to continue a bit where I left off with a non-technical explanation of what people such as myself do and my commentary on evolving technology management.</p>
<p>Here is the abstract from Unskilled and Unaware of It: How Difficulties in Recognizing One&#8217;s Own Incompetence Lead to Inflated Self-Assessments (Justin Kruger and David Dunning, Department of [...]]]></description>
			<content:encoded><![CDATA[<p>I wanted to continue a bit where I left off with <a href="http://gorrie.org/2009/11/04/what-we-do/">a non-technical explanation</a> of what people such as myself do and my commentary on <a href="http://gorrie.org/2010/01/23/agile-infosec/">evolving technology management</a>.</p>
<p>Here is the abstract from <em><a href="http://gagne.homedns.org/~tgagne/contrib/unskilled.html">Unskilled and Unaware of It</a>: How Difficulties in Recognizing One&#8217;s Own Incompetence Lead to Inflated Self-Assessments</em> (Justin Kruger and David Dunning, Department of Psychology, Cornell University), a fairly well known publication that appeared in the Journal of Personality and Social Psychology (official link unavailable):</p>
<blockquote><p>People tend to hold overly favorable views of their abilities in many social and intellectual domains. The authors suggest that this overestimation occurs, in part, because people who are unskilled in these domains suffer a dual burden: Not only do these people reach erroneous conclusions and make unfortunate choices, but their incompetence robs them of the metacognitive ability to realize it. Across 4 studies, the authors found that participants scoring in the bottom quartile on tests of humor, grammar, and logic grossly overestimated their test performance and ability. Although their test scores put them in the 12th percentile, they estimated themselves to be in the 62nd. Several analyses linked this miscalibration to deficits in metacognitive skill, or the capacity to distinguish accuracy from error. Paradoxically, improving the skills of participants, and thus increasing their metacognitive competence, helped them recognize the limitations of their abilities.</p></blockquote>
<p>This principal, known now as the <a href="http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect">Dunning–Kruger effect</a>, was given the <a href="http://en.wikipedia.org/wiki/Ig_Nobel#History">dubious honor</a> of winning an <a href="http://en.wikipedia.org/wiki/Ig_Nobel">Ig Nobel</a> prize in <a href="http://www.improb.com/ig/2000/ig-2000-details.html">2000</a>. Astonishingly enough, media from the <a href="http://www.npr.org/ramfiles/totn/20001229.totn.01.ram">NPR Science Friday show</a> that covered the Ig Nobels that year is still available 10 years later.</p>
<p><a href="http://gorrie.org/blog/../uploads/2010/01/6a00d83451b44369e200e54f4fbb538833-800wi.jpg"><img class="  alignleft" src="http://gorrie.org/blog/../uploads/2010/01/6a00d83451b44369e200e54f4fbb538833-800wi-tm.jpg" alt="6a00d83451b44369e200e54f4fbb538833-800wi.jpg" width="200" height="206" /></a></p>
<p>It seems to be part of the human condition to have trouble recognizing both competence and incompetence in matters where the observer is not at the top of their game. For example, <a href="http://en.wikipedia.org/wiki/Illusory_superiority#Driving_ability">nearly all Americans and most Swedes</a> think that they are better than average drivers.</p>
<p>This is entertaining and all, but I say this not to call attention to making fun of stupid or incompetent people in the world. Rather, how does one identify and work with people who are incompetent and not cognizant of it? What about if they are highly intelligent and are undervaluing their abilities? How does one know if ones self assessment is accurate? How can one right-size ability and decision making stature? How can one make a qualitative judgement of qualitative judgements?</p>
<p>It&#8217;s not a simple problem.</p>
<p>Certainly being a well rounded and traveled individual may help in finding this kind of clarity. This may also be something largely gained from journeyman <a href="http://en.wikipedia.org/wiki/Tradecraft">tradecraft</a>; seeing other methods and masters firsthand. This may be why people talk about risk management as being on par with a <a href="http://en.wikipedia.org/wiki/Juris_Doctor">JD</a> or <a href="http://en.wikipedia.org/wiki/Doctor_of_Medicine">MD</a>; it takes a lot of time, passion, and diligence to become and stay competent and aware and literate of the many challenges present in diverse environments and constantly moving technology. The responsibility in the design, management and assessment of complicated systems is also large. Persistent errors here can literally cost lives, crash fortunes, and wreck business models. It may be <a href="http://www.infosecleaders.com/2009/11/why-information-security-is-the-hardest-career/">one of the hardest careers</a>.</p>
<p>The massive efficiency increases to work and leisure of the last 20 years, the strides that have been taken in the knowledge of how individuals most effectively learn, and with all of the information available on the internet, affords the opportunity to learn effectively and in a disciplined approach to become and stay competent in this field. I find that many people make casual reference to <a href="http://en.wikipedia.org/wiki/Malcolm_Gladwell">Gladwell&#8217;s</a> &#8220;~10,000 hours = success in a field&#8221; rule which seems to be the take-away factoid from his book <a href="http://en.wikipedia.org/wiki/Outliers_%28book%29">Outliers</a>. I&#8217;m not really sure what to think of Gladwell and his writing, but it strikes me arbitrary. I think of competency in a large and deep field of knowledge to be like snowballs rolling down a hill; they start small, but they increase in size, depth, and have a sense of momentum.</p>
<p>Everyone can&#8217;t be a world famous <a href="http://en.wikipedia.org/wiki/Polymath">polymath</a> like <a href="http://en.wikipedia.org/wiki/Leonardo_da_Vinci">Leonardo da Vinci</a> or <a href="http://en.wikipedia.org/wiki/Johann_Wolfgang_von_Goethe">Johann Wolfgang von Goethe</a>. Genius of that level seems to be cultivated only occasionally and is not a realistic role model for nearly anyone. I do know a lot of people that are like <a href="http://en.wikipedia.org/wiki/Richard_Feynman">Richard Feynman</a> however; a pretty <a href="http://en.wikipedia.org/wiki/Competent_man">competent man</a> and likely fun at parties.</p>
<blockquote><p>&#8220;A human being should be able to change a diaper, plan an invasion, butcher a hog, conn a ship, design a building, write a sonnet, balance accounts, build a wall, set a bone, comfort the dying, take orders, give orders, cooperate, act alone, solve equations, analyze a new problem, pitch manure, program a computer, cook a tasty meal, fight efficiently, die gallantly. Specialization is for insects.&#8221; — <a href="http://en.wikipedia.org/wiki/Robert_A._Heinlein">Robert Heinlein</a></p></blockquote>
<p>I do believe that many of this ages <a href="http://en.wikipedia.org/wiki/Competent_man">competent [wo]men</a> are involved in information technology and the cream of IT are those that manage complicated systems. Certainly many of the geek cultural heros are, such as the <a href="http://en.wikipedia.org/wiki/Batman">Batman</a>, <a href="http://en.wikipedia.org/wiki/Gregory_House">Gregory House</a>, <a href="http://en.wikipedia.org/wiki/Ryo_Saeba">Ryo Saeba</a>, and <a href="http://en.wikipedia.org/wiki/The_Stainless_Steel_Rat">James Bolivar DiGriz</a>, show the common geeks aspiration to be widely competent. This may be the true root of what geek culture is all about.</p>
<p><a href="http://gorrie.org/blog/../uploads/2010/01/problemsolution.jpg"><img class="alignleft" src="http://gorrie.org/blog/../uploads/2010/01/problemsolution-tm.jpg" alt="&lt;a href=" width=" mce_href=" height="286" /></a>Predictably to those familiar with my past work, this leads back to my usual harping on metrics and data analysis instead of so called best practices, third party industry rankings, or arbitrary standards. Meaningful data is the only way to get away from the constructs of <a href="http://en.wikipedia.org/wiki/Cognitive_bias">cognitive bias</a> that lead people to fear plane crashes and terrorism but feel completely safe driving a car in nearly any condition.</p>
<p>I pose a question: can the competence of a complicated system be left to a specialist who is not competent to judge the quality of all of its components? The stakes are high after all, for what could be more important in a world that runs on the power of information but the secrets of powerful people and organizations? I contend that a <a href="http://en.wikipedia.org/wiki/Conformity_%28psychology%29">conformist</a> drive to make industry into a uniform, standard, and specialist product is directly at odds with that of producing quality work product for our industry as a whole. The business would prefer that an employee can be easily recruited, fired, or trained to <a href="http://gorrie.org/2010/01/23/agile-infosec/">perform this job</a>, but I do not believe that this is a realistic goal for risk management specifically, and perhaps, IT in general.</p>
<p>In reading one of <a href="http://www.tssci-security.com/">Andre&#8217;s</a> dives into the waters of <a href="http://www.tssci-security.com/archives/2008/06/19/rip-cissp/">competence and speciality</a>, I was stuck at his harsh but close to home hitting words about the state of the industry and professional credentials. He invokes <a href="http://en.wikipedia.org/wiki/Dan_Geer">Dan Geer</a>. Here is the preface to the talk he cites, a <a href="http://geer.tinho.net/geer.sourceboston.txt">keynote</a> at Source Boston:</p>
<blockquote><p>Good morning. If you were to come to my office, you would see on the wall these four rules:</p>
<ul>
<li>Work like Hell</li>
<li>Share all you know</li>
<li>Abide by your handshake</li>
<li>Have fun</li>
</ul>
</blockquote>
<p>And later:</p>
<blockquote><p>Only people in this room will understand what I am now going to say. It is this: Security is perhaps the most difficult intellectual profession on the planet. The core knowledge base has reached the point where new recruits can no longer hope to be competent generalists, serial specialization is the only broad option available to them.</p></blockquote>
<p>Ah there it is again. <a href="http://www.di.net/articles/archive/2020/">Serial specialization</a> might be closer to what I mean, but it is a bit hairsplitting to argue about if a skill set is <a href="http://robotic-rodents.com/category/poly-expertise/">generalist</a> or <a href="http://climbtothestars.org/archives/2009/07/09/what-if-generalist-vs-expert-was-a-mistake/">serial specialist</a>. I think the real criteria here is passion for learning and a will to do what is necessary to learn and work well.</p>
<p>I was discussing this with a friend who is a developer who has been kept pure from this circus but hears some of my tales. He had this to say when I asked him about his experience with efforts to make a homogenized software development environment. He asked that he not be named but his words from the developer side of the house sounded quite familiar to me:</p>
<blockquote><p>Having worked in a variety of industries, at a number of companies, provides one with a reasonable substrate against which to compare and contrast the natures of the environments in which one works. A set of patterns emerge that reveal the nature of an organization. Unfortunately, many of them reveal weaknesses or inefficiencies in the modern place of employment.</p>
<p>College degrees are all but an afterthought nowadays. Employers have responded by creating a set of artificial restrictions. Since I started at my current employer, a policy has been enacted by the HR department, stipulating that an applicant seeking, for example, a software development position, must hold a degree in computer science. This is a terrible idea. What does HR know about finding talented programmers? Perhaps the most talented programmers I&#8217;ve worked with have been the ones that do not hold a computer science degree. A couple of them never even finished college. An ability to excel in software development is not restricted to those who have spent years and a bunch of money on formal training in the field. As with most other crafts, a good indicator of success is the zeal with which one pursues it. Why not allow those who are responsible for developing the software determine the qualifications for those who will ultimately be hired to help build it? Senseless policies like these disempower those accountable for the work and serve as a blockade to workplace efficiency. It&#8217;s not much of a stretch to feel like HR, in situations like these, is a congressional body for the workplace, passing more and more laws as though it&#8217;s an effort to convince others that their existence is justified.</p>
<p>Something else that becomes clear after working in various employment climates is how important it is to hire really good people. This sounds like an obvious statement, but chances are you don&#8217;t even know how much this affects you. Hiring great people is what allows a company to trust employees to be able to do their jobs with minimal intervention. Being able to trust employees in this way reduces the need for artificial barriers that stand in the way of getting real work done. These policies are often in place to protect a company or workgroup from someone doing something stupid. Employers should aspire to hire good people&#8211;the best they can&#8211;across the board, so that they don&#8217;t have to annoy the good people with policies or artificial divisions of work responsibilities that mainly get in their way. This is, of course, easier said than done, but if this approach were more prominently represented in hiring practices, I suspect we&#8217;d all be better off. But, hmm, where would everyone else work?</p>
<p>Practically speaking, it seems that the companies that are known for difficult interviews are the ones that have a higher caliber of employee across the board. I&#8217;m not talking about making interviews hard and annoying for its own sake, but rather interviewing &#8220;smart,&#8221; and determining a good fit, not necessarily who has paid the right amount of money for professional training.</p></blockquote>
<p>Additionally I would like to mention that with the great responsibility and knowledge required to perform well in these critical roles, there is the sticky point of ethics and professional <a href="http://en.wikipedia.org/wiki/Due_diligence#As_a_concept_in_civil_litigation">due care</a>. The current industry standard of &#8220;<a href="http://www.giac.org/overview/ethics.php">not</a> <a href="http://www.issa.org/Association/Code-of-Ethics.html">getting</a> <a href="http://www.sans.org/security-resources/ethics.php">caught</a> <a href="http://www.isc2.org/ethics/default.aspx">being</a> <a href="http://www.sans.org/security-resources/ethics.php">a</a> <a href="https://www.instisp.org/SSLPage.aspx?pid=268">jerk</a>&#8221; is pretty weak. This relates to my point of competence and generalist/specialist bias as there is a classical example that could be considered as a useful metaphor: <a href="http://en.wikipedia.org/wiki/Bushid%C5%8D">Bushido</a>. Will has his <a href="http://cassandrasecurity.com/?p=418">own rant on the subject</a> which I recommend.</p>
<p>In the end, the world is wide and filled with wonder and things that we as humans will never fully understand. I would suggest, as an ideal, not to fear the unknown but appreciate it for the challenge that it is to do something that you haven&#8217;t done before. There will always be people who have something to teach you. Learn from them.</p>
<p>At the end of the day, it is the seasoned veterans from the trench warfare of operations and gladiatorial arenas of the boardrooms that will steer a ship to calm safe waters. Thy have the best stories, have seen the mountaintops, have looked into the yawning abyss, and have come to you to tell the tale. Are you ready to hear them?</p>
<p><small>Image References:<a href="http://headrush.typepad.com/creating_passionate_users/2006/03/how_to_be_an_ex.html"><br />
Creating Passionate Users</a><br />
<a href="http://www.wishfulthinking.co.uk/blog/wp-content/problemsolution.jpg">Dave Gray</a></small></p>
<img src="http://gorrie.org/blog/wp-content/plugins/pixelstats/trackingpixel.php?post_id=694&amp;ts=1268981977" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2010/01/24/generalists/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://www.npr.org/ramfiles/totn/20001229.totn.01.ram" length="122" type="audio/x-pn-realaudio" />
		</item>
		<item>
		<title>Agile Infosec</title>
		<link>http://gorrie.org/2010/01/23/agile-infosec/</link>
		<comments>http://gorrie.org/2010/01/23/agile-infosec/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 12:45:00 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[agile]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[complicated systems]]></category>
		<category><![CDATA[engineering]]></category>
		<category><![CDATA[generalist]]></category>

		<guid isPermaLink="false">http://gorrie.org/?p=683</guid>
		<description><![CDATA[<p>This is a reprint of my comment to a Joshua Corman&#8217;s posting on The Fudsec Blog. Consider going there to read his article and the discussion that followed.</p>
<p>I can&#8217;t link to my comment there and, since I&#8217;m going to continue down the rabbit hole on this particular topic, I wanted to be certain that I [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://gorrie.org/blog/../uploads/2010/01/printing_plate.jpg"><img class="alignleft size-medium wp-image-685" title="printing_plate" src="http://gorrie.org/blog/../uploads/2010/01/printing_plate-300x199.jpg" alt="" width="240" height="159" /></a>This is a reprint of my comment to a <a href="http://twitter.com/joshcorman">Joshua Corman&#8217;s</a> <a href="http://fudsec.com/do-the-evolution-1">posting</a> on <a href="http://fudsec.com">The Fudsec Blog</a>. Consider going there to read his article and the discussion that followed.</p>
<p>I can&#8217;t link to my comment there and, since I&#8217;m going to continue down the rabbit hole on this particular topic, I wanted to be certain that I had a link to reference should internet churn happen.</p>
<blockquote><p>I see where you’re trying to go here, but I’m not quite with you.</p>
<p>First, the OODA loop can easily turn into the usual Hamster Wheel of Pain as Jaquith mentions in his book <em><a rel="nofollow" href="http://www.amazon.com/gp/product/0321349989?ie=UTF8&amp;tag=badpen-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=0321349989">Security Metrics: Replacing Fear, Uncertainty, and Doubt</a></em>. If you shared the link entitled <em>On Sheep, Wolves, and Sheepdogs</em> with non-insiders, I believe most people would find it offensive. People don’t like being called a sheep because they don’t understand the dizzying details and byzantine process and pitfalls of our industry that is largely driven by irrationality. I also don’t really find it directly relevant or constructive in a complexity and technology risk management discussion, though it is if someone objected to carrying a gun in church.</p>
<p>After talking with <a href="http://twitter.com/wgragido">Mr Gragido</a>, him bring up this blog entry, my saying that I had read it already, and his encouraging me to join the conversation, I find myself ready to talk about some of the same talking points that I’ve been bringing up for the last couple of years:</p>
<ul>
<li>relevance</li>
<li>metrics</li>
<li>unjustifiable complexity</li>
<li>over-specialization</li>
<li>mental inflexibility</li>
</ul>
<p>First, most of what everyone in the industry speaks about is entirely irrelevant to business. Completely. If the information security profession wants to be taken seriously, they need to be relevant and speak in terms that the business will understand. Everything else I bring up is in line with this first point.</p>
<p>Second, almost nothing is measurable. There are many workflows, scorecards, risk valuations, and frameworks, but nearly all of the time, they are not put in terms that the consumers of risk information find relevant. Metrics need to be automated (cheap to gather) and meaningful.</p>
<ul>
<li>Measuring if past implementations have been effective or if the ROI was achieved after the unforeseen operational costs. Basing decisions on rich data case study would be great and also nearly completely unavailable.</li>
<li>No information sharing between consumers anywhere. There is no Consumer Reports for enterprise technology. Every vendor or analyst has their hand out and it significantly colors their recommendation findings IMHO. Enterprise doesn’t share the data that matters.</li>
<li>A vulnerability scanner provides what is the worst kind of metric; one that isn’t meaningful to anyone. The risk practitioner knows that it is only a faction of appreciable risk, a non-practitioner looking at a scorecard may draw unjustified conclusions based on the score delta, etc.</li>
</ul>
<p>Third, with all this talk about cloud computing, people seem to be forgetting that cloud computing is not anything new. It’s distributed computing bundled with an API and given a fluffy concept to be marketed. This is not helping anything. If we as an industry are going to add a bunch of additional layers to the old conceptual model, we do not need to evolve, we need to optimize. I’ve asked around. Almost no one knows what we do. We’re the <a rel="nofollow" href="http://www.surlalunefairytales.com/books/dutch/griffis/woodenshoe.html">gnomes that fix their shoes at night</a> and lead people to believe that their shoes fix themselves. If we’re going to accept giant expansion of the threat landscape in accepting massively insecure Web 2.0 applications and, at the same time, accept outsourcing all of our data to complex distributed systems where it intermingles with everyone elses data in a way that people throw up their hands, as it is too complex, and declares “it is in the cloud,” someone needs to appreciate that they are making this risk decision. It is our responsibility to communicate this. No one else will do it.</p>
<p>Fourth, people have become way too specialized to the point of not understanding what their actions have on other teams. It may be the case that literacy in many areas of our practice is hard. As complexity increases, the amount of people who will be up for it will decrease. The dispassionate that only came for a day job that pays a lot of money will not care enough to do what it takes to get their hands around it. We need to be clear that this complexity we’re developing will accelerate the <a rel="nofollow" href="http://en.wikipedia.org/wiki/Peter_Principle">Peter Principal</a> of technology and technology-dependant business management. I find it interesting that <a rel="nofollow" href="http://en.wikipedia.org/wiki/Management">Technological Management is a stub here</a>, though I am not surprised. We need to work toward a middle ground so that communication can happen on a level playing field. <a rel="nofollow" href="http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project">ASVS</a> may help us to do this.</p>
<p>Fifth, and finally, best laid plans need to be right-sized on the ground. A mechanic’s touch needs to be worked into human resource valuation. Flexibility and agile organization has to be valued more than the ability for bad managers to find someone else to blame for the systematic problems that they have had a part in creating. Complacency is too widespread. Complacent organizations are driven by the minimum standards of compliance. Leaders do not talk much about compliance as it is way in their review mirror.</p>
<p>If we as risk managers can not put risk in terms that the decision makers and shareholders can understand without calling them sheep or cattle, then we are not worth anything. If we can’t make the argument inside of the technology discussion, what chance do we have translating that to those who do not have an interest in technology?</p></blockquote>
<img src="http://gorrie.org/blog/wp-content/plugins/pixelstats/trackingpixel.php?post_id=683&amp;ts=1268981977" style="display:none;" alt="pixelstats trackingpixel"/>

<p>Related posts:<ol><li><a href='http://gorrie.org/2009/11/04/what-we-do/' rel='bookmark' title='Permanent Link: What we do'>What we do</a></li>
<li><a href='http://gorrie.org/2010/02/12/the-politics-of-respect/' rel='bookmark' title='Permanent Link: The Politics of Respect'>The Politics of Respect</a></li>
<li><a href='http://gorrie.org/2007/11/12/itci-2007/' rel='bookmark' title='Permanent Link: ITCi 2007'>ITCi 2007</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2010/01/23/agile-infosec/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
