OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Antonomasia (ant_at_notatla.demon.co.uk)
Date: Sat Oct 26 2002 - 18:09:59 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    From: Alan Cox <alanlxorguk.ukuu.org.uk>

    On Sat, 2002-10-26 at 16:01, Yousry Kassieba wrote:

    > > job..can you imagin that i have got all this wealth of experiecnce and i
    > > have cannt find a job in computer security audit field
    > >
    > > CAN any one tell me why is that?

    > Because people don't wish to pay for security, just moan about the lack
    > of it. Security doesn't add to the short term bottom line, inflate the
    > stock price and let the management run off with a load of money.

    Those who do have a job doing security stuff don't get things all their own
    way. You may actually get the chance to audit code in the workplace. But
    if it's written by another department in your company what do you think it
    will take to get it fixed ?

    I could do an off-topic rant on a pile of things but I'll let you escape
    this time. Suffice to say that tying the hands of the security staff is so
    common that the reason for employing them is more likely to be PR than
    implementation of objective security measures. So why would the security
    staff need any experience ?

    Suppose I'd better mention this too:
        http://www.cl.cam.ac.uk/~rja14/econsec.html

    -- 
    ##############################################################
    # Antonomasia   ant notatla.demon.co.uk                      #
    # See http://www.notatla.demon.co.uk/                        #
    ##############################################################