{"id":2549,"date":"2020-07-28T09:15:34","date_gmt":"2020-07-28T13:15:34","guid":{"rendered":"https:\/\/zzzptm.com\/wordpress\/?p=2549"},"modified":"2020-07-28T09:15:34","modified_gmt":"2020-07-28T13:15:34","slug":"understanding-security-get-your-metaphors-right","status":"publish","type":"post","link":"https:\/\/zzzptm.com\/wordpress\/?p=2549","title":{"rendered":"Understanding Security: Get Your Metaphors Right"},"content":{"rendered":"\n<p>Forget any analogies dealing with pitched battles.&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/security-professionals\">Security professionals<\/a>&nbsp;are not generals, foot soldiers, commanders, admirals, missile base commanders, gunfighters, or X-wing squadron leaders. Thinking that we are such things puts us in the wrong frame of mind, where we&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/expect\">expect<\/a>&nbsp;a conventional conflict. Even if such a conflict is edged in trickery or clever&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/deception\">deception<\/a>, it&#8217;s simply not how things work in information security. We&#8217;re more in a world of trickery and clever deception, sometimes edged with conventional conflict, if anything.<\/p>\n\n\n\n<p>If we want comparisons to professions, we need to look at spies, pest exterminators, librarians, cattle ranchers, and forest rangers. These are people who manipulate knowledge, guard&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/assets\">assets<\/a>, and who deal with hidden threats. If you still want&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/military\">military<\/a>&nbsp;metaphors, I&#8217;ll allow people clearing minefields, sentries, codebreakers and&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/intelligence\">intelligence<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/analysts\">analysts<\/a>&nbsp;(although those are technically spies), and military police. Let&#8217;s get rid of the glamour and focus on the dirty work, OK?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,h_671,q_auto,w_880\/v1\/post-attachments\/respect_fryuqe\" alt=\"\"\/><\/figure>\n\n\n\n<p>There are two major reasons to come up with the right metaphors and examples for cybersecurity. One is so that we get ourselves into good habits of mind for dealing with threats. Two is so that we can use real-world explanations to help people outside of the profession understand that we don&#8217;t simply identify all the PCs running &#8220;Hacker.exe&#8221; and then blow them up.<\/p>\n\n\n\n<p>I&#8217;ll even dare to say that much of our profession has a connection to&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/organizations\">organizations<\/a>&nbsp;that make us all uncomfortable. While I don&#8217;t want the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/nsa\">NSA<\/a>&nbsp;to harvest all of&nbsp;<em>my<\/em>&nbsp;data, I&#8217;m perfectly ready to recommend massive&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/data-harvesting\">data harvesting<\/a>&nbsp;to organizations wanting to improve security. While I&#8217;d hate for my wife and&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/kids\">kids<\/a>&nbsp;to&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/spy\">spy<\/a>&nbsp;on&nbsp;<em>me<\/em>, I&#8217;m always advocating that we set up as many&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/sensors\">sensors<\/a>&nbsp;and data collectors as possible in a customer environment, even getting PCs to&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/report\">report<\/a>&nbsp;on each other.<\/p>\n\n\n\n<p>In other words, you know you&#8217;re a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/security-professional\">security professional<\/a>&nbsp;when you read&nbsp;<em>1984<\/em>&nbsp;to get ideas about doing your&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/job\">job<\/a>&nbsp;better.<\/p>\n\n\n\n<p>Now, not everything in this series will go dark like that. Then again, dark is what we all deal with, so don&#8217;t be surprised to find metaphors in that region. They may not necessarily be the metaphors you want to share to explain the profession to others, but they could very well be the metaphors that&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/unlock\">unlock<\/a>&nbsp;the habits of mind you need to improve your focus.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Forget any analogies dealing with pitched battles.&nbsp;Security professionals&nbsp;are not generals, foot soldiers, commanders, admirals, missile base commanders, gunfighters, or X-wing squadron leaders. Thinking that we are such things puts us in the wrong frame of mind, where we&nbsp;expect&nbsp;a conventional conflict. Even if such a conflict is edged in trickery or clever&nbsp;deception, it&#8217;s simply not how [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-2549","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2549"}],"version-history":[{"count":1,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2549\/revisions"}],"predecessor-version":[{"id":2550,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2549\/revisions\/2550"}],"wp:attachment":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}