When Getting the Audit Done is the Only Thing

George Finlay · EDPACS · 2003

Last winter, I delivered a one-day security session at a conference in London, England. My topic was “Securing Your Place on the Web” and I had about ten attendees. In a competing session in the room next door, there were at least 50 participants. That session's topic was “Hacking Web Applications.” Mind you, the speaker for the other session was excellent and may have put a few extra bodies in the seats, but his ability to deliver an entertaining session didn't account for the difference. At the time, I remarked to several colleagues that this phenomenon was indicative of a malaise sweeping the audit and security professions. People don't want to learn about the underlying technology; they just want to know what to do to complete the audit and wow their bosses who also might not understand the technology.

Read the paper · More papers on PaperTik