Pages

Showing posts with label intent. Show all posts
Showing posts with label intent. Show all posts

Wednesday, October 8, 2014

Motivation, Engagement, and Leadership

One of the hardest things about my job is maintaining engagement and motivation in my team.

I'm sure many of you are nodding in agreement.  People are the hardest part of any leadership job, and for people like me who rose through the technical ranks people are a whole lot different to engage than routers, switches, servers, and SANs.

I know everyone has a story about the temperamental server that, if ignored, would slowly fail but with a little TLC and a periodic check would run happily forever.  There may even be a lesson inside those experiences.

My CIO is one of those rarefied technology people who can actually give a sense of warmth, closeness, and caring.  You can feel that she sincerely cares about the people around her.  In our staff meetings, we make time to talk about our company and organizational culture; the company's social contract and our perspectives on what the contract is telling us.  A few weeks ago she shared this link with us and asked for our perspective:

Is Your Company Culture Affecting Your Employee Engagement?

I read this article several times, picking up on new ideas both from the article and how companies are following, or not following, the principles presented.  As I thought about this article and looked back on back to presentations from CEOs, I remembered one of Flip Flippen's mantras for The Flippen Group: No organization can rise above the constraints of its leadership.

Employee engagement is inherently limited by the personality of company leadership.  That made me think about some of the ideas I'd heard from CEOs:

"A" people hire "A" people.  "B" people hire "C" people.

This CEO explained their perspective that "A" people were the top-level performers in the organization, the 5% doing 50% of the work.  "B" people were the 9-to-5 workers, the one who punch the clock and get a paycheck, fulfilling and even excelling at their duties but generally not exceeding them.  "C" people were the one barely scraping the minimums of their duties in quantity or quality, resulting in the need for additional work to complete tasks.

The CEO's view was that "A" players wanted to be surrounded by other "A" players, focused on accomplishing goals through whatever investment needed to get there.  "B" players didn't want to be shown up, such they would hire "C" players to ensure they looked good compared to others.  "C" players were of limited to no value.

He coached his leadership team to focus on the "A" people, work to eliminate the "C" people, and limit the influence of the "B" people.


I want my leaders to be aggressive, taking business away from our competition.

This CEO expressed that his ideal leadership team was made up of highly competitive, highly aggressive leaders.  He wanted a leadership team focused on wresting away business from the competition, taking calculated risks to attack the sales positions of competition and gain favorable market share.

This leader made it a point to talk about business ethics, focusing on the need to earn and retain business based on acceptable practices, a point he recognized as necessary given the highly aggressive nature of his team as they used (almost) any means necessary to gain the upper competitive hand.


I want Type A people, self-starters who seize problems and push people to drive them to conclusion.

This CEO explained that Type A personalities were the ones that got things done.  He coached his leadership on how to be Type A, how to identify a Type A player, and how to develop and promote Type A players into leadership positions.  It was his goal to build a team full of Type A people who wouldn't pause in the pursuit of company objectives.

Type B players, by contrast, were needed to do daily work, but the lack of pure drive for accomplishment meant they were best relegated to less senior positions.  The CEO coached his leadership to help develop assertiveness and need for achievement as a requisite for advancement into leadership of the company.


So, to be honest, I'd been affected by each of these presentations.  I let myself be somewhat swept up in their (much better presented) points of view.  Organizations are all about accomplishing goals, achieving new things.  By extension, clearly things like drive, assertiveness, aggressiveness, were the traits that made such possible.

I reflected on myself and others - am I an "A" player?  Are my team "A" players?  Am I aggressive enough?  Am I Type A?

For those of you at home keeping score:
- "A" Player: Not my call, but my leadership consistently says "yes"
- Aggressive: I have a small aggressiveness pool, which I tend to only I feel backed into a corner.
- Type A: No.  I'm a Type B.  One word: reflective.

My CIO sends this article, and I start to think.  29% of workers are actively engaged.  What percentage of the population is an "A person", "Aggressive / Competitive", and "Type A" (or could coach themselves to be close)?

I bet it's less than 29%.

I bet most companies are burning the Type A wick to cover their big productivity needs; a select few companies are figuring out how to unlock the other 71%+.

The comments from those CEOs show how a leader can hold back an organization.  You can't build a team of high-drive, high-aggressive, high completion-oriented people and expect it to stick together.  Such organizations are powder kegs; the explosions can be somewhat directed to rapidly accomplish a goal, but the harm the explosions cause results in those organizations splintering and failing to produce long-term results.

Start-ups are a great example.  Sudden bang, then wholesale replacement of staff and leadership to turn rapid initial progress into long-term value.  Failure to bring in long-term, sustainable staff will reduce value to the point of either company failure or acquisition for intellectual property rather than inherent value.

No one wants to buy a company that relies solely on overworking and stressing staff to accomplish its goals.

Life is a marathon, not a sprint.  So it is, or should be, in business.  Sprints may deliver an initial victory - assuming the finish line is close enough - but the marathon runner will ultimately surpass the sprinter's accomplishments and deliver victories over and over again.

The article made me realize that the long-term success of a company really comes down to the diversity of its leadership, a diversity that must be as broad as the people who work for that leadership.  Each employee needs different treatment and handling to coax the best out of each of them, and only complete appreciation and understanding will accomplish that goal.

So what does this mean?

The value of an individual is not based on easy-to-define categories.  There's no single magic formula for a high-performance team, or a high-performance individual - because there's no single formula for a person or team who can transform to be high performance.

The magic is awareness.  Be aware of the strengths and limitations of each employee.  Be aware of what motivates each employee.  Be aware of how each employee reacts and responds to work, life, and circumstance.

Be aware of how your statements and actions influence your employees; in other words, be aware of how your leadership may be inhibiting the growth and future of your employees.

Stay engaged with your team.  Build a means to communicate.  Use that opportunity to give feedback, good and constructive.  Use each individual's strengths to help them grow, adapt to manage their vulnerabilities to limit their impact on the future.

And don't be part of their problem.  No organization can rise above the constraints of its leader, and no member of a team can rise above the constraints of their organization.

Wednesday, October 1, 2014

BMW Drivers Suck

That's right.  BMW drivers suck.  All of you.

I was riding with our normal Tuesday/Thursday group south on White Chapel Boulevard near Bob Jones Park.  Our group is pretty orderly (well, usually), and that day we were riding downright politely.  We had a nice single-file line moving up the road, with the lead rider pulling off to the left in a slow rotation.

If you're not familiar with this area, which many of you probably are not, this section of White Chapel Boulevard is a 30mph two-lane country road with 2-6" of shoulder right of the white line.  It provides access to neighborhoods north of TX114 near the south side of Lake Grapevine.  Since these neighborhoods do provide access back to the south, it's not technically dead-end, but the road is only useful as access to those neighborhoods.

It has a huge park with ballfields and soccer fields (football, for the rest of the world), playground, a dog park, and miles of lakeside hiking trails.  It has two schools along it, horse farms, and lots of open space.

In other words, a perfect road for bicyclists.  Out of the way, quiet, pretty, and lined with facilities that encourage outdoor sports and activities.

So we're riding this road, as we do every Tuesday and Thursday.  There's a mean little hill that rises out of a creek bottom perhaps a quarter mile from the elementary school.  There's always south wind in Texas, and this is a southbound section of road.  It's not a big climb (this is Texas), but it's punishing and we tend to ramp up the effort to make up for the lack of pitch or length.

I'm leading the single-file pack up this hill.  I've hit my limit for suffering, so I wheel off to the left, letting the next rider continue the push as I slide backwards relative to the line to find an open spot.

We're probably only doing 20mph or so.  We may be quick, but we're not world class.

I get about 3 wheels back when a BMW 760LI blows by me, engine roaring as the driver accelerates hard.

When I say he blow by me - and I assume it was a "he", it's a typically male car, being driving in an escalated-testosterone-level way - I mean he passes me with inches to spare.

And when I said inches, I mean precious few inches.

I have the image of the passenger mirror missing my handlebars by such a small margin that I had cognitive dissonance - I was still upright, but my conscious was curiously thinking I was flying through the air.  The blast of air of the 50mph car (in the aforementioned 30mph zone) probably augmented the reality.

As I say: BMW drivers suck.  All of them.

Sadly (and, perhaps, funny at the same time), many of my cycling friends are nodding their heads in agreement.  There's no doubt that the, shall we say, "more financially endowed classes" are more likely to treat vulnerable road users (like cyclists) like scum.

(Transparency: My wife and I just bought a Mercedes-Benz.  A *used* MB.  6 years old, because we can't afford a new one.  And we hope it doesn't break down because we can barely afford to fix this one.)

But that's an aside; not just a statement about BMWs, but a statement about many premium brand owners.  I'm talking about BMW owners.  They suck.

Right?

Of course not.  There's clearly at least one BMW driver that sucks.  One BMW driver that has no respect for other's life or well-being.  One BMW driver defines all BMW drivers.

Unfortunately, like most people, cyclists tend to unfairly lump people into groups.  I've done it at least twice in this post, and I'm about to let loose with a little bit of our little "club's" prejudices.

Our perspective is different from most, which makes for interesting conversation.

I've had fewer little problems with people who are in the lower end of the socioeconomic scale.  For whatever reason, those drivers tend to make room and be in less of a rush.  This seems to cut across almost every race and creed.

There are a lot of Mexicans and Central Americans in Texas, and from a cycling perspective I'm glad.  There's no doubt that some look at me funny, but they are absolutely respectful on the roads.  When I see them working as landscaping / lawn crews, they go so far as pause work and slow their weed-whackers, leaf blowers, and lawn mowers so I don't get a blast of clippings as I pass.  (That happened again last night - some people are awesome.)

Don't worry.  The local Caucasians make up for it - except for country folk.

I have few problems when riding around the country.  If anything, country folk are the people I enjoy riding around the most, aside from their absolute passivity when driving.  I've had farmers and ranchers sit 100' off my wheel for minutes waiting for a passing opportunity delivered on a golden platter accompanied by light from the heavens and angels singing.

That does not apply to certain groups of rednecks, however, who seem to relish the opportunity to throw objects, buzz, or belch fume-laden diesel smoke on anyone that triggers their feelings of inadequacy.

Rock haulers are downright scary.  I think drivers would agree with me.  Frac trucks aren't much better.

I have never once had a negative encounter with anyone remotely resembling a Muslim.  Never.  Every single case has been respectful.

But with that in mind, there are places where I feel more in control of my survival during rush hour than I do on Sunday mornings before church.  Between the relatively poor driving of older folk (which I'm rapidly becoming) and some "God will be PISSED if I don't run down this cyclist who could make me late to church!" mentality, certain roads can be downright dangerous.

That's right.  Practicing Christians are part of the problem.

And that brings it back full circle to our BMW driver.  BMW drivers suck.

I know it's not fair, and perhaps that's precisely the point.  If you don't like how you, or your "group", are perceived, change it.  If you don't like how you're lumped into a "group", don't do it yourself.

And, please, don't drive like an asshole.  Thanks.

Friday, June 27, 2014

The Rules...and Life

No matter how you feel about them, The Rules have some truths about cycling, and life, worthy of consideration.  I'll admit, I don't follow all the rules, I am not a Velominatus, but I do subscribe to some of the ideals that it represents, both on the bike and off.

When you look at the real intent of the rules, you see it's really about being committed.  In cycling, there's a certain aura, even mystique, to being a roadie; reading these rules you can see that.  From color matching on the bike and color-coordination in the kit (clothes), to well-tended tan lines, using kilometers (instead of miles), and only allowing espresso and macchiato (instead of coffee or lattes).

I also suppose you're only allowed to take dainty sips from white china with your pinkie finger out while holding the tea plate in your other hand underneath.


I suppose it's ok to use plastic if you're on the team bus prepping for the next stage.
Side note, if you ride / race and don't drink coffee, 1) more power to you; and, 2) you should.

Deep down, the rules aren't just about cycling; they're about life.

As the Rules say...
...it's all about looks.  Appearance is everything in road cycling, and many roadies will quickly rate those around them by how closely others tend to their appearance; the better kept a cyclist is, the more they follow the written and unwritten rules of form and fit, the more respect they get.

Rule 7: Tan lines should be cultivated and kept razor sharp.

The ring of lighter-colored skin above the deeply-set tan earned through hundreds of hours outdoors on the bike: it's unattractive, and looks unkempt.

This can be hard, even for people like me, as kit can vary in fit, but there's also a practical reason to keep tan lines sharp: burns.  There's nothing worse than having a perfect tan line at the bottom of the shorts with a quarter-inch burn ring just above it.  It hurts, and it looks terrible.

Rule 8: Saddles, bars, and tires shall be carefully matched.


Isn't she beautiful?
I cringe whenever I see a bike with different color tires, wheels that don't match or are the wrong color for the frame or tires, bright bar tape that doesn't match the palette of the frame.  It's like seeing a car with different wheels on it; the owner simply doesn't keep up with maintenance or doesn't pay attention to details.

Rule 33: Shave your guns.

Let's be honest: there's always tells; at a bicycle ride hairy legs is one of them.  I'll be the first to admit there are some strong, talented, hairy-legged (ew) people out there; I didn't shave my legs until I finally got serious enough to buy a real bicycle, and that was only 3 years ago.  But, in general, hairy legs means quick dismissal.

Rule 53: Keep your kit clean and new.

This really speaks for itself.  Dirty clothes are dirty (and look dirty).  Clothes wear out.  Don't let your inability to maintain a wardrobe result in you looking sloppy.
Looking Pretty.

On the surface these rules can seem unfair, and even a little bit prejudiced.  By my experience, however, it's also generally true: you can judge a cycling book by its cover.

The rule really is this: always look better than you have to.  Cyclists may take this in a certain direction, setting specific rules to maintain a mystique, but in the end it's really about representing yourself in the most positive light.

Whether it's mismatched kit or a novice-level knot on a tie, never forget that appearances count.  Look good, and you'll be received well.  Look good, and you may have the opportunity to do well.


Another aspect of the rules...
...is about being a positive contributor.  Cycling, and life, is full of people who don't contribute, don't bring light to the life around them.

Rule 67: Do your time in the wind.

No cyclist likes wheelsuckers, people who use the draft solely to their benefit without making a contribution.  Cyclists especially detest wheelsuckers who do so then take off in the dwindling miles to leave behind the people who did all the work.

We all know wheelsuckers, people who only work to grab the coattails of someone else's successes.  We even know a few who have made an art of sprinting ahead of hard working people to claim completion and credit.

Earn what you receive.  Do your time in the wind.

Rule 19: Introduce yourself

Although this is a little about networking, it's a little more about joining existing social networks.  Joining an existing club ride can be very daunting, especially for a new cyclist; and even for veteran riders there's plenty of pitfalls.

Take the time to introduce yourself.  Learn who the group is, and who the primary people are - who the leaders are.  Learn the rules, and follow them.

Rule 43: Don't be a jackass

As a common group, cyclists share a common perception from others.  It's absolutely critical that we think of what our actions may mean for the greater community.  What we do could come around to haunt someone else, whether it's immediate response to something we do or adding to pent-up emotion that results in someone's action later.

This is true in all things.  Be respectful of those around us, treat people fairly - as they would want to be treated.  Earn karma, and help others pass it along.


Finally, the last bit of advice from the Rules...
...is about commitment and dedication.  Like in life, cycling will only give what you put in, and sometimes you have to put in a hell of a lot more than you're going to get out - pay it forward.

Rule 10: It never gets easier, you just go faster.

Training to get faster, to get stronger, never gets easier; in fact, the effort and regiment necessary to gain becomes greater and greater as your capability grows.  You may get out of training what you put in, but the returns decrease over time - faster by smaller and smaller increments.

You have to build a system in which to grow, and you have to dedicate to that system in order to get anything out of it.  Life never gets easier, you just gain more experience and knowledge to deal with it.

Climbing a hill is like wrestling a gorilla.  You don't stop when you get tired.  You stop when the gorilla gets tired.

Rule 9: If you're out riding in bad weather, it means you're a badass.  Period.

Riding in the cold, wind, rain, snow (or some combination) is the sign of insanity - or complete dedication.  It's not about passion, it's about commitment.
A rainy 42F in February, and we're racing

Such as it is in life.  It's not always bright skies, warm days, light winds; more often than not life throws in a challenge we must surmount.  Whether it's 100F+ temperatures, 30mph winds, or changes at home or at work that rock the boat of our lives, it's those that get out there with a smile and dedication to move forward that will ultimately gain and grow for the experience.

Rule 93: Descents are not for recovery.  Recovery Ales are for recovery.

Reaching a peak doesn't mean the end of the road (except in mountaintop finishes, but even then typically the race goes on the next day).  The race continues, and the descent off the top is no time to stop putting in the effort to stay ahead of the pace.

Success starts early, even immediately following success.  Don't relax; use each pinnacle to drive for more, perhaps higher opportunities.  There will be time to recover and prepare for the next chase, be sure to wait until that opportunity comes before starting to relax.

Rule 64: Cornering confidence increases with time and experience:
This pattern continues until it falls sharply and suddenly.

Falling on a bicycle sucks, well and truly, and nothing does more to shatter riding confidence than to have a major wreck.  Unfortunately, they happen, sometimes because of our own confidence, and sometimes because the world is a difficult place.
...and this is going to suck.

We all suffer failures, on the bike as well as the lesser parts of life.  Physical wounds from these failures take time to heal; challenging ourselves to outperform our past will help heal our mental injuries, and only through that will we begin again to gain and grow.

Rule 5: Harden the F**k up (HTFU)

Cycling is hard.  You're in a pack, halfway up a climb.  45 miles in, 17 to go.  The pace has been brutal, and even now the tempo is painful as you work the sustained 8% grade.  Your legs are screaming so loud you can't hear your own breathing over the sound.

Through the fog...you see it.  The head flick.  The glance over the shoulder.  Then it happens, someone attacks.  A moment passes, then someone chases.  From within the oxygen-deprived, heart-pounding, lactic acid-fueled haze, the voice: chase, or lose.

This is absolutely not about "getting over it."  You don't get over it, but you do have to bear it.

Opportunities don't only come when you're prepared to chase them.  Sometimes you have to grit your teeth and work through the pain of failure, loss, and hard work to grab on to something truly valuable.

Life is hard.  You just need to be harder.

But, really, it comes does to one thing in the end:

It doesn't matter how fast you go...you must never give up.

Progress is progress.  I've hit the wall so hard I could barely balance on the bike for how slow I was moving; many of us have.  We just have to keep going and we'll eventually get there - where ever there may be.

And that's how it is.  You don't have to chase every break, you don't have to always be at your best.  You don't always have to be primped and polished, and you don't always have to have a smile on your face.

You do have to keep moving.  It's only through that effort that you'll find yourself in a different, hopefully better place.

And remember Rule 4: It's all about the bike.

Wednesday, June 25, 2014

Focus on Fundamentals

Ok.  Let's face it.  The fundamentals are hard.  They're also boring.

They're also fundamental; they're the foundation.  Nothing can survive (long) without a foundation, and success will ultimately be limited by the limitations of the foundation on which that success is built.


In bicycling, our foundation is called the "base".  Base is earned through long miles in the saddle riding at a consistent and moderate pace, repeated over and over.  The typical training plan has 2-3 months of this stuff, mile after mind-numbing mile, as much as 3-4 days a week, with length based on how long races will be later in the year.  60 mile races?  4+ hours on the bike getting in base.


So, yeah, it's hard, and it's boring.


Bicycling, and Information Security, are both like building a pyramid.  If you want to go faster, ride longer, you need to build a wider base first.  You need a solid foundation, one that will support you when the time comes to drive a break 70 miles into a 100 mile race.


Information Security is the same.  If you want to deliver better protection, higher capability, you need to ensure you have a complete and supporting foundation - fundamentals.  If there's cracks or missing sections, there's room for the whole system to collapse under the weight of the stacked stones.

That raises the (obvious) question: what is fundamental to information security?  You have to have Anti-Malware.  And a Firewall.  Mix in some Intrusion Detection, log analysis.

Fact: none of those are fundamental.

Seriously.  You don't need this.

Put down the pitchforks for a moment.  Use of technologies like these are absolutely required, they just don't make up the foundation of a solid information security program.


So what does?


The National Institute for Standards and Technology (NIST) has put together some excellent documentation about managing information technology and information security.  One of their recent products is the CyberSecurity Framework, a product that provides a clear and executable map to measuring information security risk in a practical and illustrative way.


One of the key components of NIST's model is the list of core functions: Identify, Protect, Detect, Respond, Recover.



The Sequence of Core Functions - Each Drives the Next

These are sequential risk-reduction, information security management functions.  Investment only provides mitigation to the right, such investment is best served further to the left.  That means your foundation is the item to the left: Identify.



You can only act on what you've delivered.
Stealing liberally from NIST's documentation, this is what Identify means:

Develop the organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities

Understanding is fundamental to information security, the level of understanding is the ceiling for any information security program.  And understanding is hard, we always want to fast forward past it to get on to the sexy part of information security (if such a thing exists).

But you cannot secure that which you do not understand.  So let's dive in:



Understand Business Strategy


Information Security cannot operate without alignment with business purpose and strategy.  Use this knowledge to capture (or develop) a list of Threats that apply to the business model, vulnerabilities of the business based on the line of work, then cross to find enterprise class risks.  It is here that technology and information risks can be latched.


This is where we'd capture "Risk Tolerance", and a good place for a short soap box.  Risk tolerance should be a dying term as it's typically used in place of "willing ignorance": a willingness to accept risk due to perception the risks can't manifest (i.e., don't apply).  Risk tolerance should be a business case, financial-driven decision based on potential losses and impact of manifest risk.  But I digress.


This is where the information security program will take root and where it'll find reliance and support as it delivers business cases for risk reduction; the Why of Information Security.



Establish Management Intent

Utilize the knowledge generated in understanding the business strategy to establish over-arching management intent.  This starts with the Security Policy; the policies, procedures, and standards designed to deliver controls that orient to the risks the organization faces. 


The quickest, easiest way to establish intent is to select a control framework and write it into Policy and Procedure.  This becomes a simple process of selecting controls that relate to the risk posture of the company, setting standards within those controls according to the level of risk, and establishing metrics and measurements to enable assessment of compliance to controls.


Intent should also integrate Information Security into other organizations, enabling upstream and downstream delivery of controls throughout the organization.  Information Security has cross-organizational concerns in Vendor Management, Human Resources Management, among others.


The intent of Intent is to establish the rules for how security will operate, aligned to the risks and strategies of the company; the How of Information Security.



Capture Inventory


This isn't a real Datacenter.

This is where the rubber meets the road in the statement "you cannot secure that which you do not understand."  In practical terms, this inventory is the list of stuff that needs to be protected.  There's a lot to think about, but they fall into a few broad categories with the depth of detail driving the maturity of downstream controls.  This is the "What" of Information Security.

Design and Architecture Assets: Network and system diagrams, the "as-built" for the technology system as a whole.

Physical Assets:  There are the traditional technology devices with a few added items.  Servers, laptops, mobile devices, printers, network equipment, security equipment.  Each should be uniquely identified via some electronic means, each should have pertinent information such as responsible part, purpose, and similar.


Service Assets: These are the delivered technologies supporting business functions, such as the HRMS, FMS, ERP, along with smaller services such as Reporting, Project Management, and other solutions.  These should have owning business organizations and/or responsible individuals associated to each.

Integration Assets: Flow diagrams showing the movement of information between services (information systems) and the relationships of business processes to information flow.

Software Assets: The list of approved operating systems and software packages utilized on the environment.

Information Assets: The types of information utilized and where they are intended to be located with owning business organization and/or responsible individuals.

Identity Assets: The complete list of individuals who should have some level of access to the technology systems with information on their role and area of responsibilities.

Access Control Assets: The complete list of defined access credentials for each service and system, and a complete list of the roles and privileges provided within each.

(It's hopeful, and hopefully likely, that the Identity and Access assets are already linked; else, this is low hanging fruit.  Get it done.)

Threats and Vulnerabilities: The last two are a little less palpable but no less important, the list of Threats and Vulnerabilities within the organization.  These are necessary to create a risk profile for the assets inventoried above, enabling decisions on how to deliver protection, detection, response, and recovery in appropriate measure.

Threat Inventory: A list of known potential sources of impact to the organization's technology systems.  This list should be based on the inventory generated above; i.e., threats that are specific to the technologies and services being consumed; and based on how the business is operated, linking threats to parties that may be interested in disrupting the services provided, such as organized crime for retail.

Vulnerability Inventory: A list of known vulnerabilities within the environment.  This should be developed by both technology (scanning) and research, and contain vulnerabilities that impact information security and the application of controls over technology such as environmental and human influences.


It is all about the fundamentals; it's not possible to implement an information security program without having a strong grasp on what needs to be secured, why it needs to be secured, and how it should be secured.  The Identification process provides the knowledge needed to define the necessary technical and procedural mechanisms of information security.


Sorry.  Obligatory.
Without having a solid foundation, vulnerability manifests in cracks, eventually manifesting as failure in controls and, possibly, failure in the information security program.

Sometimes in spectacular fashion.  The pyramid comes crashing down because of a single failed stone.

The investment in time in fundamentals will lead to a more successful program.  Take the time to figure out the gaps, act on them, and the program will be better for it.

Friday, May 16, 2014

Avoiding Hyperbole

Yes.  I heard about Target.

It happens every time.  Something big happens.  The news outlets turn on the bullhorn.  Affected constituents (customers) drive the furor.  Punditry on the event and effects.

Someone asks me about it on our group ride, expecting a reaction in line with what they've seen in the news.  Hyperbole, exaggeration, sky-is-falling.

(Heartbleed was probably a rare understatement of the risks.)

As an information security professional, I seize these moments to drive attention to the risks every company has when it dabbles in technology.  These moments provide a unique opportunity to add a little more darkness, a little more creaking wood and whistling wind to resident fears.

"Could it happen to us?"  Yes.  (Intellectually inaccurate, but too deep for the moment.)

"What should we do about it?"  I'm glad you asked.

This is where the conversation would typically flow toward talking about dollars, gee-wiz technologies with brilliantly flashing LEDs, all resulting in the constant whirr of user hard drives, CPUs sweating as cooling fans desperately try to overcome the heat of constant workload.

But that's not where this conversation goes.  Yes, I need money for my security program.  Everyone does.  I have another avenue I need to pursue first.

Security in our technological environment is like controlling a swimming pool.  We work very hard to maintain it, but we're constantly struggling with algae, PH levels, crap dropping from trees or deposited by wind.  Let alone the people who use it; they're the worst thing that a pool could ever experience.  Sweaty, suntan-lotion covered, beer (margarita!) drinking, swimmy-wearing people.

We put up fences to keep undesirable people out.  We have water surface alarms to warn us when the kid, the dog, (or a stranger) tries to take a dip without our knowledge.  We even have heaters and coolers.  Or wondrous, LED-filled technologies; automated pool management systems that keep water temperature just so, keep PH in range, automatically turn on lights; it even alerts me when anything is out of line.

Of course, if I can't do the fundamentals, if I can't keep water levels up, if I can't keep the chlorine basket filled, if I can't consistently empty the filter, I'll eventually turn off the pool automation alerts.

Sound familiar?

I want consistency in controls.  I control where the refill water comes from, the same way every time.  I control who can use my pool, and what they have to do before entering.  And, no, there's just no peeing in my pool.  Even in the shallow end.

Security is like that swimming pool.  Simply put, your pool is only as good as the worst part of it.  Try leaving a section of algae in your pool next time, see how that works for you.

Verizon has great charts describing how breaches occur, and those datapoints are incredibly important.  Knowing where the vulnerability manifests, critically important.  Just don't turn them into a game of whack-a-mole.

The real lesson from Target is that controls must be consistent in order to be effective.  Leave aside all the discussion about ignored warnings, missed opportunities; ask yourself these questions:

Why was a critical, protected infrastructure accessible from common, low(er) security networks?

Why was a third party, any third party, connected into a company network without documentation; worse, lacking separation from general corporate systems, let alone critical infrastructure?

What are the core security competencies, the core controls in alignment with business risk necessary to protect the operations of the company?

And, root cause for Target: Why wasn't there a single point of authority over all information security to serve as the foundation for application of standards and compliance?

Target's CEO's departure is the final nail, and with due respect a righteous kill.  Management never had intent to implement solid security controls, and such never named an individual to have ultimate responsibility for those controls.

There's my message.  No, Target can't happen here.  you, Mr(s). Executive, express management intent to maintain security - which is why I'm here.  I intend, first and foremost, to be solid in the basics; to do the basics consistently flawlessly.  Your intent to support that mission is imperative.  We'll talk more when, with your support, I've driven the risk out of the fundamentals.

And, yes, I'll need money to do it.  We need to know there isn't a peeing section in our pool.

Tuesday, May 13, 2014

On Intent

My first blog, my first post.

I've intended to start a blog for a long time, but I always found a way or reason not to do it.  I can be easily derailed; the last stutter before I started this blog was whether I would compose under a pseudonym or my real name.  I believe what I say, and such intend to be open and public about my thoughts; yet, as you can see, I decided not to follow my intent and have gone somewhat incognito.

Before that it was the decision which blog service to use.  I intend to use easiest to access, easiest to use service; instead, I found that Google had a blog engine and just ran with that.  Naturally, that means if you hunt around enough on Google+, you'll find me.

I intend to also make everything easy, which by my nature makes it all difficult at the same time.

I guess I live intentionally; to coin a phrase.  Sometimes I live intentionally to do what I intend; other times I intend to not to what I intended, break the mold and live outside what I would expect of myself.  All that means is that when I get outside the box I'm still walking familiar paths.  I'm still in the box.

Much of my life is spent in the idea of "intent".  The work I do can be described as "setting intent", the concept that I describe the attainment of certain, high level organizational goals, guiding the activities, means, and methods in accomplishing those goals.

I also measure (read: police) our attainment of those goals, but that's a conversation for another time.

The idea of organizational intent, leadership intent, is a powerful one.  Simple statements made in a single breath by someone with positional authority becomes work responsibilities for a team of staff.  Intent sets the stage for everything; it puts the focus on what is important, and de-emphasizes what isn't.  It tells us where we're going, why we're going, what we're going to, and how we're getting there.

Who: those dedicated to setting and achieving that intent.  Are you in?

Intent is powerful.  It provides meaning, purpose, it gives definition to what we do and understanding to why we do it.  And it applies everywhere.  I am an avid bicyclist; I intend to be faster than I am today, stronger than I am today.  That intent drives me, sometimes even consuming me.  I am unwilling to accept my limitations.  I am unwilling to live within the confines of my current abilities.  I intend to break through; get a few more seconds on the rivets before I pop (and then a few more); get a few more watts out of tired legs; stay on the wheel of that competitive racer for just a few more pedal strokes.

Intent is powerful.  It's also dangerous.

All too often, we fail to set or properly describe our intent.  We never know what we're trying to accomplish.  We never know what we need to accomplish it.  We never know how to get help, and others don't know what we're doing to offer to help.  Rudderless and windless.

When we set intent, we still must be intentional about it.  Intent is directive: it can be collaborative, engaging, community; or it can be individual, solitary; but must be a decision, and it must be action.  Intent is worthless when there is no decision to act; nothing accomplished, frustration results.

Spirits fly on dangerous missions
Imaginations on fire
Focused high on soaring ambitions
Consumed in a single desire
In the grip of a nameless possession --
A slave to the drive of obsession --
A spirit with a vision is a dream with a mission...
Rush, Mission

Together we'll find out how dangerous intent is, at least with regards to my intent to start a blog.  I intend to make this an interesting read, covering a variety of subjects within my interests.  I'll range from cutting-edge science (less about the field of science, more about significant discoveries) to application of technology, fitness and nutrition, musings on other subjects that might strike my fancy.  Oh, and bicycling; there'll be plenty of opportunity to read about my passion for the bicycle.

I don't intend to cater to everyone's interests, but rest assured if someone suggests a subject I'll have a few words to share about it.

Thanks for taking the time to read my inaugural post, I hope you'll join me as we start this journey.

-- TechieRoadie