Book

The Process of Security

by Bruce Schneier · 2000 · 1 reading card

1 card

  1. The Process of Security · 2000

    The certificate is a photograph, and security is the film it was cut from.

    Schneier's sentence is a quarter of a century old and still the best objection to compliance treated as a destination. A certificate says that, on the audit days, a sample of evidence matched the requirements. The system that produced that evidence can be abandoned the next morning and the certificate stays valid until the next surveillance visit. The certificate is a photograph; security is the film it was cut from. Hence the practical test for any compliance programme: if a control only works when an audit approaches, the control does not exist, only audit preparation does. The signs are easy to spot: a year of access reviews all performed in the same week; logs collected retroactively; training completed by everyone in three days. ISO/IEC 27001 is built against exactly this pattern, because it requires measurement (9.1), internal audit (9.2), management review (9.3) and corrective action (10.2). That is cadence, not an event.

    Security is a process, not a product. Products provide some protection, but the only way to effectively do business in an insecure world is to put processes in place that recognize the inherent insecurity in the products.

    Open the card