Enter your Email


Powered by FeedBlitz
Ted Demopoulos Ted's contact info
Ted lives in Durham, New Hampshire, USA, with his wife Margaret, children Jamie, Amelia, Anastasia, and dog Tyler. He consults and gives keynotes on Technology, Security, and Business. He loves flyfishing, ham radio, and great food and wine.

Main Website

Keynote Speeches

Free Articles

securITy Newsletter

More about Ted

Atom/RSS feed

Add to My Yahoo!

Subscribe with Bloglines

Subscribe in NewsGator Online

Hair Loss and Replacement Advice

Cheap Printing

Kevin Trudeau Free Money

Tabletop Christmas Trees

Female Hair Loss and Replacement Advice

Champagne, magnums, splits

Christmas Yard Decor

Rock and Roll History

Aluminum Christmas Tree

Security Certifications

Build and Share Online Lessons

Silver Christmas Tree

Free Video Playlists

Valentine Day Gifts

Computer Security Training

•Profitable College Speaking Bootcamp

•Striped Bass Fly Fishing

•College Speaker

•Shopping Carts for Blogs and Websites

•Book Reviews

•Masters Information Security

•Need a Shopping Cart?

•Security Laboratory

•Become a Published Author and Public Speaker

•SANS Security Training

•Geekonomics

•Security Thought Leader

Avoiding “Worst Practices,” or praying at “The Temple of Best Practices.”

Full Article at http://www.demop.com/WorstPractices.htm

The “Best Practices Mantra” annoys me.

I define “Best Practices” as practices validated by experience and common sense. Often the “common sense” component is entirely skipped and the “Best Practices Mantra” is used as an excuse for not thinking. That includes not thinking about what “Best Practices” actually means. A quick google reveals lots of “Best Practice” links and “Best Practice Institutes,” but none of them bother to define “Best Practices.” No one bothers to define the Bible or Koran either, but I would argue that they do not need to be defined, and are certainly not fads. The jury is out on “Best Practices” . . .

I was at a new client’s facility yesterday and when I asked about certain security practices and configurations, I often got the blanket statement “Best Practices” as an answer. It was clear in several cases that these alleged “Best Practices” either did NOT apply or were INCORRECTLY implemented. In both cases no one had used their common sense and had instead chosen to place their blind faith and prayers at the “Temple of Best Practices.”

Hence we kick off our Worst Practice series with:
Worst Practices in Best Practices
Practices to avoid like the plague!!!!

1) Assuming all Best Practices apply. Few Best Practices are universal.

2) Turning off your brain while implementing and using Best Practices. Nothing is foolproof, and you should always apply common sense.

3) Implementing Best Practices and thinking you are done.Nothing is static; that includes Best Practices.

4) Implementing Best Practices without avoiding Worst Practices. One major blunder can negate everything!

Comments on "Avoiding “Worst Practices,” or praying at “The Temple of Best Practices.”"

 

post a comment

      
      

Most Internet users have been targeted by criminal phishing emails, yet less than one third have any idea what phishing is, and only 3.5% have changed their habits due to the threat of phishing!

Risks include Identity Theft, Credit Card fraud, and more.

Download Results (pdf)