Friday, March 12, 2010

Bookmark and Share

Archive for the ‘Teleological suspension of the ethical’ Category

McAfee: “Ethics First” Apparently Isn’t

You ever seen McAfee’s business ethics pledge? In case you haven’t, they call it “Ethics First” and they proclaim it loud and proud on their website:

We are committed to holding the highest ethical standards. Our business relationships with customers,
shareholders, employees, suppliers, and local communities must always be built on a foundation of integrity and trust. We call this commitment “Ethics First”

Bookmark and Share

ISC(2) Under Investigation for Plagiarism

For those of you unfamiliar with my opinion on the CISSP, I’m not a huge fan. It’s not that I’m against certification per se, it’s just that I question the value of the cert and I think ISC^2 is the wrong body to administrate such a cert. I think, for example, that a for-profit entity has an economic incentive to push as many people through the process as possible, thereby lowering the quality of the certification over time. Additionally, I’m of the opinion that CISSP doesn’t really do much for the public at large and doesn’t do much for practictioners like other professional certifications (CPA, license to practice medicine, etc.); unlike other professional certifications, it doesn’t prevent malpractice, it doesn’t provide recourse for individuals who have been burned by poor-quality security professionals, etc. At best it’s of questionable value; at worst it’s a cash-cow for the licensor.

In any event, given my feelings on the topic, I was interested to read that ISC(2) is under investigation for plagerism in the “Official” CISSP guide. Apparently, an entire chapter in that book has (allegedly) been copied and pasted verbatim into the book from a paper from the American Bar Association. There are (allegedly) additional materials “borrowed” from a number of other sources as well. For those unfamiliar with the CISSP, there is a mandatory code of ethics that accompanies the certification. The following are all entries from theISC^2 code of ethics:

-Act honorably, honestly, justly, responsibly, and legally.
-To discorage behavior such as… Associating or appearing to associate with criminals or criminal behavior.
-Tell the truth; make all stakeholders aware of your actions on a timely basis.
-Avoid conflicts of interest or the appearance thereof.
-Take care not to injure the reputation of other professionals through malice or indifference.

Is it me, or in the light of those aspects of the code, that this ISC^2 plagerism is particularly noxious. It’s not just the fact that they stole from others – it’s the hypocrisy of making other people swear to uphold the code that they violated in an official publication of theirs… on no less than 5 counts.

Bookmark and Share

Shady Verisign Dealings

Well, Verisign has done it again. One of the bidders for the .net domain has gone on the record saying that there are factual issues in the published recommendation. The register, did some digging and found out that (surprise, surprise) there are serious conflicts of interest with several members of the evaluatory commitee. Pretty standard and transparent stuff, really. Evaluators with a monetary and/or personal interest in favoring their chosen pony and no compunction against slanting the evaluation criteria, ignoring technical experts, etc., etc. My question about this is, though: why is Verisign even allowed to bid?

Don’t people remember that time that Verisign tried to hijack DNS to make money on all our collective typos? Remember when ICANN had to strongarm Verisign and threaten them publicly in order to make them comply? Paul Twomey (ICANN president) said in a statement:

“…VeriSign

Bookmark and Share
“Our promise to our customers is that the intelligence, analysis, and research we provide lives up to the highest standard of integrity.”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (1)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (1)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives