A Step Inside the Guerilla CISO’s Mind
July 31st, 2008 by rybolovIf you're new here and would like to see more of what I'm saying, you may want to subscribe to my RSS feed (I can even email my blog posts to you when I publish a new one) or have a look at my papers and presentations page for downloads of stuff that you can share or "borrow heavily from". You also might find my guidelines for posting comments interesting, especially if you're a government employee. If you want to see me blog about anything in particular, drop me a private email on how you think I'm completely full of myself, extend me an invitation to speak at your next security meeting/event, or just to ship a huge bag of money in my direction, you can do that through my contact page. Thanks for visiting and happy hacking!
I toyed for several years about making an infosec hall of shame. Like seriously, I already had some candidates, you know who most of them are, it’s the same as the Washington Post Front-Page Metric.

Hall of Fame, Hall of Shame photo by leafar.
And my friends and I had some other nummy tidbits from our travels out and about, doing this stuff in the place where theory meets the realities of implementation.
Now if you look around on The Guerilla CISO, you’ll find that I don’t have a Hall of Shame. I eventually decided not to have one after much deliberation, and the reason is this: If you have key decision-makers that are removed or abstracted from the impacts of the decisions that they make, it is not fair to publicly humiliate the people who have to live with the implementation of the decisions.
And for better or worse, that’s the way the Government’s security model (and many other things) works.
Posted in The Guerilla CISO |
3 Comments »
Posts RSS























