Policy makers make the policy that must be followed. Of course the engineers would take the brunt of blame, even though the engineering groups never make policy.
Its easy to say someone being personally responsible would fix the problem.. Really this just encourages further nefarious organizational behavior. I.e. hiring people into big titles who can't even understand their liability and railroading them into what an informal management actually wants as far as risk/cost trade offs which are then even higher toward risk as there is a scapegoat.
Let's presume this is a company, who would you say should take the fall for this?
The CEO will have to talk about it and manage the fallout. What else are you looking for.
Also, at this point we have no idea how they got in, until we know I think we should withhold judgement. Unless you consider yourself responsible if someone ever gets into a system you manage with a zero day.
Security is not an exact science, it's a trade-off between sensitivity of the data and the cost of protecting it whether you like it or not
Punishment isn't an exact science either, and there will be some arbitrary decisions that will be taken in order to find a trade-off between visibility and responsibility, whether you like it or not
I have the same with a pair of jeans, I bought the same pair 3 times but now they start to wear down and I have been trying to find another pair but no luck.
It works well in Germany. For products too, at least what I tried. The last time I did a very German product search (association-management software) the first hit was a comparison on golem.de, which is pretty solid.
I find myself adding a !g bang when searching for products in the Netherlands, only to find out that the Google product results are NOT better than Kagi's
Reading more books is a stupid goal, there were years were I read 40 books but didn't absorb anything. Reading needs multiple passes and some time to think about what you've just read.
reply