<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bad Penny &#187; fail</title>
	<atom:link href="http://gorrie.org/tag/fail/feed/" rel="self" type="application/rss+xml" />
	<link>http://gorrie.org</link>
	<description>bound to turn up.  The adventures of an early adopter.</description>
	<lastBuildDate>Tue, 22 Jun 2010 05:37:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>My talk at Seattle Toorcon 2008</title>
		<link>http://gorrie.org/2008/04/19/toor08/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=toor08</link>
		<comments>http://gorrie.org/2008/04/19/toor08/#comments</comments>
		<pubDate>Sun, 20 Apr 2008 05:52:38 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Presentations]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[jail]]></category>
		<category><![CDATA[toorcon]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/04/19/toor08/</guid>
		<description><![CDATA[<p>I gave a little talk this weekend at the second Seattle Toorcon.</p>
<p>My presentation is as follows, though as usual, I ad lib when presenting. Video may appear in the future.</p>
<p></p>
<p></p>
<p>The compliance game: The enemy of good</p>
<p></p>
<p>Lots of execs have the idea that technology is a cost center and not the bedrock that enables their business to [...]]]></description>
			<content:encoded><![CDATA[<p>I gave a <a href="http://seattle.toorcon.org/2008/conference.php?id=40">little talk</a> this weekend at the <a href="http://seattle.toorcon.org/2008">second Seattle Toorcon</a>.</p>
<p>My presentation is as follows, though as usual, I ad lib when presenting. Video may appear in the future.</p>
<p><span id="more-304"></span></p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08001.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08001-tm.jpg" alt="Toorcon Seattle 08.001.jpg" width="133" height="100" /></a></p>
<p>The compliance game: The enemy of good</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08002.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08002-tm.jpg" alt="Toorcon Seattle 08.002.jpg" width="133" height="100" /></a></p>
<p>Lots of execs have the idea that technology is a cost center and not the bedrock that enables their business to function.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08003.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08003-tm.jpg" alt="Toorcon Seattle 08.003.jpg" width="133" height="100" /></a></p>
<p>This leads to reckless activities caused by not treating risks to their information systems as they would other business risks, (and also because of what has become the usual reactions to fraud and appropriate disclosure to investors getting punked)</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08004.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08004-tm.jpg" alt="Toorcon Seattle 08.004.jpg" width="133" height="100" /></a></p>
<p>So, with Sarbanes-Oxley and others, now if you&#8217;re an exec and you aren&#8217;t doing the job you were hired to do,</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08005.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08005-tm.jpg" alt="Toorcon Seattle 08.005.jpg" width="133" height="100" /></a></p>
<p>they can put you in jail when it all hits the fan.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08006.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08006-tm.jpg" alt="Toorcon Seattle 08.006.jpg" width="133" height="100" /></a></p>
<p>Wait! I&#8217;m an executive! Jail is bad! I don&#8217;t want to go to the rape camp!</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08007.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08007-tm.jpg" alt="Toorcon Seattle 08.007.jpg" width="133" height="100" /></a></p>
<p>What should I do?!?</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08008.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08008-tm.jpg" alt="Toorcon Seattle 08.008.jpg" width="133" height="100" /></a></p>
<p>Typically, you can overreact and, instead of doing what you should have been doing in the first place, you can do something that is <span style="font-style: italic;">obviously</span> better; you can dump as much money as you can find at the perceived problem of making sure that your surpass the standard of due care in your industry to be &#8220;above average.&#8221;</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08009.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08009-tm.jpg" alt="Toorcon Seattle 08.009.jpg" width="133" height="100" /></a></p>
<p>Bring in the consultants! You need to be better than average else you might be going to camp. Since everyone has to be better than average, costs and efforts increase and increase.</p>
<p>This is the same reason that executive compensation is 100s of times greater than the average employee in America.</p>
<p>[ Someone should come up with a better behavioral term for this. ]</p>
<p>So, in much the same way executive compensation is on geometric curve, compliance standards follow.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08010.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08010-tm.jpg" alt="Toorcon Seattle 08.010.jpg" width="133" height="100" /></a></p>
<p>So are you safe now?</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08011.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08011-tm.jpg" alt="Toorcon Seattle 08.011.jpg" width="133" height="99" /></a></p>
<p>Does this fix problem? Yes!</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08012.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08012-tm.jpg" alt="Toorcon Seattle 08.012.jpg" width="133" height="99" /></a></p>
<p>Well. Kinda&#8230; or maybe not at all.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08013.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08013-tm.jpg" alt="Toorcon Seattle 08.013.jpg" width="133" height="99" /></a></p>
<p>Maybe even worse than before you spent all that money</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08014.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08014-tm.jpg" alt="Toorcon Seattle 08.014.jpg" width="133" height="99" /></a></p>
<p>This will likely give great improvements to those that are way behind, but it can also defeat it&#8217;s own efforts.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08015.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08015-tm.jpg" alt="Toorcon Seattle 08.015.jpg" width="133" height="99" /></a></p>
<p>One of my favorite examples of compliance gone wild is password enforcement:</p>
<p>Since passwords are such a foolproof way to police complicated systems and responsibilities, deploying a system to strengthen authentication isn&#8217;t what you should do.  You should really just change passwords a lot.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08016.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08016-tm.jpg" alt="Toorcon Seattle 08.016.jpg" width="133" height="99" /></a></p>
<p>Oh. They should also be increasingly complicated so that no average worker will remember them. You should also make them change it every week or two on a ton of systems so that your workers spend a lot of time changing and forgetting their passwords&#8230;</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08017.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08017-tm.jpg" alt="Toorcon Seattle 08.017.jpg" width="133" height="99" /></a></p>
<p>unless they start writing lists.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08018.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08018-tm.jpg" alt="Toorcon Seattle 08.018.jpg" width="133" height="99" /></a></p>
<p>But we tell them not to do that! Guess what. Everyone does it. If it&#8217;s not in a hard copy hidden under their keyboard or a collection of post-its, then they are cached on their workstation somewhere&#8230; or a bunch of enable passwords in their wallet. I&#8217;m sure you can find an example of this in the next office of a public company you&#8217;re hanging around.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08019.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08019-tm.jpg" alt="Toorcon Seattle 08.019.jpg" width="133" height="99" /></a></p>
<p>Another great one is segregation of duties. It&#8217;s the idea that every role&#8217;s responsibility should be paired with another role that will catch them if they&#8217;re being shady and vice versa. It&#8217;s foolproof! What an awesome plan!</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08020.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08020-tm.jpg" alt="Toorcon Seattle 08.020.jpg" width="133" height="99" /></a></p>
<p>Where it may be the case that it is somewhat effective in prevention or commoditization of their workers, what is assured is that in complex technical environments, no one person or team will be equipped to deal with the interdependent systematic problems.  Unfortunately, those tend to be the really critical ones.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08021.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08021-tm.jpg" alt="Toorcon Seattle 08.021.jpg" width="133" height="99" /></a></p>
<p>Segregation of duties for audit and risk frameworks when too zealously applied mean that skills become specialized and no individual is allowed to have a complete understanding of operations. If no one retained on staff has a effective holistic understanding of complicated systems, solutions can become piecemeal and unreliable. Staff retention becomes a larger problem as tasks become more repetitive and narrow.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08022.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08022-tm.jpg" alt="Toorcon Seattle 08.022.jpg" width="133" height="99" /></a></p>
<p>You can always try mind control.</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08023.jpg"><img src="http://gorrie.org/blog/../uploads/2008/04/toorcon-seattle-08023-tm.jpg" alt="Toorcon Seattle 08.023.jpg" width="133" height="99" /></a></p>
<p>In summary and in short, nothing fixes companies that are doing it wrong. This is because the deterrent of fines is treated as a cost of doing business and the idea of public shaming of bad behavior seems not to be effective. We are left to choose between the threat of jail and fines. Jail is too much of a motivator and leads to over-reaction, and overblown controls which can be (and usually are) counter-productive to what is good. Fines can be ignored as a cost of doing business. Their efforts to be &#8220;perfectly compliant&#8221; can become the enemy of good business and efficient environments. Look for these behaviors in the future, and attempt to resist more controls to counter the controls that they are there to control.</p>
<p>..or alternatively for this audience, become familiar with their practices and work to exploit their many weaknesses.</p>
<img src="http://gorrie.org/blog/wp-content/plugins/pixelstats/trackingpixel.php?post_id=304&amp;ts=1283834769" style="display:none;" alt="pixelstats trackingpixel"/>

<p>Related posts:<ol><li><a href='http://gorrie.org/2009/07/16/toorcamp/' rel='bookmark' title='Permanent Link: The Trials of Toorcamp'>The Trials of Toorcamp</a></li>
<li><a href='http://gorrie.org/2010/04/09/metrics/' rel='bookmark' title='Permanent Link: The Art of Keeping Things Done'>The Art of Keeping Things Done</a></li>
<li><a href='http://gorrie.org/2007/11/12/itci-2007/' rel='bookmark' title='Permanent Link: ITCi 2007'>ITCi 2007</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/04/19/toor08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  gorrie.org/tag/fail/feed/ ) in 0.65452 seconds, on Sep 7th, 2010 at 4:46 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Sep 7th, 2010 at 5:46 am UTC -->