Part 6: Taking Control of the Stick

Part 6: Taking Control of the Stick

One cold — but rarely addressed — reality of Information Security is the “institutional attack vector.” Practitioners are battling against attackers from around the globe, from private individuals to state sponsored teams. They also battle against the basic insecure foundation of Internet protocols and personal computer operating systems. Add to that list poor programming techniques and the ever-dissolving edge of what they have to protect. However, there is another battle just as difficult and just as removed from their sphere of authority: the very business they are endeavoring to protect.

Information Security practitioners often face the challenge of battling the business. These battles take the form of coping with simple policies to facing complex issues like BYOD and compliancy. It’s rare for the business and the security office to be partners, because the security office is not observed at the board level.

Likewise, the security office is often not thinking at the board level, but happily isolated in the technology. In such cases the Information Security Office is not business enabling but business adverse, further isolating its participation and influence.

The question becomes, how would professionalizing this field help drive solutions?

A recently released report, "Professionalizing the Nation's Cybersecurity Workforce? Criteria for Decisionmaking," by the National Research Council (2013), concluded that cybersecurity is still too new to professionalize standards for its practitioners. The National Research Council’s arguments against professionalizing fall into three categories. In the first category, the council’s claim is that the knowledge, skills, and abilities required of the cybersecurity workforce are so dynamic that one cannot effectively establish a baseline for professionalization. Next, they claim that the knowledge and competencies required by the cybersecurity workforce are too broad and diverse to enable professionalization. Lastly, they state that at a time where demand for cybersecurity workers far exceeds supply, professionalization would create additional barriers to entry.

The questions, if observed with a historical context, might find parallel associations in other nascent times when disruptive technologies emerged. The American Medical Association (AMA) was founded in 1847 to address one of the very same issues: a lack of professionalization in the medical field. During the early nineteenth century, the major concern was a medical profession increasingly overrun with self-taught practitioners, only some of who knew what they were doing. Risk to the public was simply too great to bear, and a movement began to minimize “self-taught practitioners” and professionalize the industry.

The AMA accelerated the professionalization of medicine and the establishment of minimum standards in medical training, education and apprenticeship requirements to gain entry to the profession. The same could and should be done in the Information Security field with a similar cybersecurity national body and professional associations.

The Department of Homeland Security released a recent paper entitled, “The Path towards Cybersecurity Professionalization: Insights from Other Occupations” (2014). The paper makes a comparison of the similarities between the professions of Aviation and Cybersecurity. The aviation industry has a number of categories of pilot that include student, sport, recreational, private, commercial and airline transport. All levels require different training and licensing.

In contrast, the National Research Council in its report, “Professionalizing the Nation’s Cybersecurity Workforce? Criteria for Decision-making” (2013) stated that cybersecurity is still too new a field in which to introduce professionalization standards for its practitioners. Yet a similar break down of “pilots” for cybersecurity has already occurred from the National Initiative for Cybersecurity Careers and Studies (NICCS) with the National Cybersecurity Workforce Framework 2.0 (NCWF). The framework assembles similar types of cybersecurity work into seven broad areas of practice - securely provision, operate / maintain, protect / defend, investigate, collect / operate, analyze and oversight / development.

Francesca Spidalieri and Sean Kern, in an excellent paper titled, “Professionalizing Cybersecurity: A path to universal standards and status” from the Pell Center (2014), noted that the American Board of Medical Specialties has 24 general certificates and 125 subspecialty certificates. In terms of depth and breadth, Information Security does not appear to be any more complex than other professionalized occupations.

The National Research Council report against professionalizing went on to state that the knowledge, skills, and abilities required of the cybersecurity workforce are so dynamic that one cannot effectively establish a baseline for professionalization. A counterargument seems clear: in such dynamic times, an expectation of coalescing direction and business alignment from such chaos is highly unlikely.

Francesca Spidalieri and Sean Kern’s paper provides guidance to help professionalize the cybersecurity workforce following the traditional model of professionalization as represented by the medical profession and suggests a number of broad steps.

  1. Create a nationally recognized, regulatory body to serve as a clearinghouse for the cyber-security profession, similar to the AMA in the medical field.
  2. Establish member professional associations for each specialty.
  3. With these in place, develop a common body of knowledge (CBK) for each specialty. These bodies will then establish and maintain rigorous standards of training and education along with establishing certification/licensing requirements.
  4. To complete the training and certification an establishment of apprenticeships and residency requirements in each specialty will be developed.
  5. Finally, establish a standard code of ethics.

About the Author

Martin Zinaich is the information security officer for the City of Tampa’s Technology and Innovation department. The insights in this article were shared at a Wisegate member event, where senior IT professionals discussed these pressing security issues.

Featured

  • It Always Rains in Florida

    Over the years, and many trips to various cities, I have experienced some of the craziest memorable things. One thing I always count on when going to Orlando is a massive rainstorm after the tradeshow has concluded the first day. Count on it, it is going to rain Monday evening. Expect that it will be a gully washer. Read Now

    • Industry Events
  • Live from GSX 2024 Preview

    It’s hard to believe, but GSX 2024 is almost here. This year’s show runs from Monday, September 23 to Wednesday, September 25 at the Orange County Convention Center in Orlando, Fla. The Campus Security Today and Security Today staff will be on hand to provide live updates about the security industry’s latest innovations, trends, and products. Whether you’re attending the show or keeping tabs on it from afar, we’ve got you covered. Make sure to follow the Live from GSX page for photos, videos, interviews, product demonstrations, announcements, commentary, and more from the heart of the show floor! Read Now

    • Industry Events
  • Elevate Your Business

    In today’s dynamic business environment, companies specializing in physical security are constantly evolving to remain competitive. One strategic shift these businesses can make to give them the advantage is a full or partial transition to a recurring revenue model, popularly called a subscription service. This approach will bring numerous benefits that not only enhance business stability but also improve customer relationships and drive innovation. Recurring monthly revenue (RMR) or recurring annual revenue (RAR) are two recurring cadence choices that work simply and effectively. Read Now

  • Playing a Crucial Role

    Physical security technology plays a crucial role in detecting and preventing insider cybersecurity threats. While it might seem like a stretch to connect physical security with cyber threats, the two are closely intertwined. Here’s how physical security technology can be leveraged to address both external and internal threats. Read Now

Featured Cybersecurity

Webinars

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3