Re: Forrester analyst on India's cybersecurity policy

Milind Bhargava <[email protected]>
Newsgroups gmane.org.telecom.india-gii
Message-ID <[email protected]>
It's their level of incompetence that is the problem.

Regards,

Milind Bhargava
Sent from my iPad

On 2013-09-02, at 9:44, Suresh Ramasubramanian <[email protected]> wrote:

> The good thing is such people can almost never achieve the required level of competence.
> 
> --srs (iPad)
> 
> On 02-Sep-2013, at 18:33, Milind Bhargava <[email protected]> wrote:
> 
>> Like all politicians abuse power once they have some, how can we trust half a million people to not abuse their ethical hacking knowledge for personal gains. I am in the security field and most people I meet want to learn the same so they can hack gmail/yahoo and Facebook. Even if someone doesn't say most of their questions in the end turn to the same.I won't say I have never been tempted to abuse what I know, it's hard but you need some self discipline and you can do it.
>> 
>> Coming back to the likes of Ankit fadia institutes, they download tools and books online and say they can teach all security exams in 1 course. They can never be used to train a cyber army, more like upcoming script kiddies.
>> 
>> Regards,
>> 
>> Milind Bhargava
>> Sent from my iPad
>> 
>> On 2013-09-01, at 18:31, Suresh Ramasubramanian <[email protected]> wrote:
>> 
>>> Your assessment matches mine about there being a substantial copy and paste job from multiple best practices, the government CISO idea is also an import.
>>> 
>>> Finding people will be difficult as you say.  As for respecting fundamental values, you have different agencies in India, some of which may have a mandate at cross purposes with what is described here.
>>> 
>>> It entirely depends on on the ground implementation - even though whichever way it is done, it figures to be a windfall for vendors of security products and training. That is the case Even if all this is done the right way and, to use your example, the dslr actually gets its features used to the max.
>>> 
>>> --srs (iPad)
>>> 
>>> On 01-Sep-2013, at 23:35, Banibrata Dutta <[email protected]> wrote:
>>> 
>>>> No kidding... an IT-sec army that is about half the size of our army !
>>>> Forcing a role like CISO, sounds similar to mandating Head-CSR. I hope similarity ends there, and doesn't turn into another lip-service position.
>>>> 
>>>> What good it will do -- well I agree, it will give the NIITs and other such informal IT finishing-schools a shot in the arm... and some more business for the likes of Ankit Fadia. However, not sure that it is going to bring about a radical change in the chalta-hai system, where pretty much every government and small-business organization uses Gmail, Hotmail and Yahoo accounts. Computer Security as a subject is taught in BE/B.Tech, BSc(Comp Sc.), BCA, MCA etc. or at least forms a chapter of some IT subject, so it's not that people don't know what it is. However teaching cyber forensic, true-blue black-hat, hacking/anti-hacking skills to really counter the East-Europe, Chinese and such onslaught would take quite some effort.
>>>> 
>>>> Also this augurs well for firms selling security appliances (and we can expect a windfall for them, thanks to that fiscal incentives thingy). I hope that in the frenzy, everybody doesn't rush to buy those with default settings -- much like an average joe buying a top-of-the-line-DSLR and then using the "auto" mode to click snaps. Defeats the whole purpose.
>>>> 
>>>> The real gem there in that article however, was --
>>>> 
>>>> Respect for fundamental values: All strategies place a strong emphasis on the need for cybersecurity policy to respect fundamental values, which generally include privacy, freedom of speech, and the free flow of information.
>>>> 
>>>> Hard to tell, how honest government is about that statement (I really and truly suspect), but is good to hear never the less.
>>>> 
>>>> PS> Sorry, but this may sound a bit pessimistic. I am no security expert (rather far from it), but throwing half-a-million people at a complex, fast-evolving, high-technology related problem isn't perhaps as simple and easy as it may sound.
>>>> 
>>>> 
>>>> On Sun, Sep 1, 2013 at 6:40 PM, Suresh Ramasubramanian <[email protected]> wrote:
>>>>> He raises a set of points (positives) that are worth looking at, and invites
>>>>> discussion.
>>>>> 
>>>>> It would be useful to have such a discussion on gii ..
>>>>> 
>>>>> http://blogs.computerworlduk.com/security-and-risk/2013/08/is-india-geared-up-to-handle-the-dynamics-of-cyber-age/index.htm
>>>>> 
>>>>> --srs
>>>>> 
>>>>> _______________________________________________
>>>>> India-gii mailing list
>>>>> [email protected]
>>>>> http://india-gii.org/cgi-bin/mailman/listinfo/india-gii
>>>> 
>>>> 
>>>> 
>>>> -- 
>>>> regards,
>>>> Banibrata
>>>> http://www.linkedin.com/in/bdutta
>>>> http://twitter.com/edgeliving
>>> _______________________________________________
>>> India-gii mailing list
>>> [email protected]
>>> http://india-gii.org/mailman/listinfo/india-gii

_______________________________________________
India-gii mailing list
[email protected]
http://india-gii.org/mailman/listinfo/india-gii
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.