Sunday, November 8, 2020

Is infosec overrated?

This might not be the best forum to post this question in but since its mainly networking guys in here I'll put it across from more of a networking POV. Infosec guys are overrated, I've worked 2 companies with them in (both really nice guys) but as far as "contributing" or "knowledge" goes, there's nothing a infosec person does that a networking guy couldn't do either. They're glorified buzzword people that write essays and pass them to the higher ups who haven't got a proper grasp on things as well but see all the buzzwords and worries in the essays handed to them and then it either goes to networks or infrastructure for those guys to actually DO IT! Majority of the time this has happened with me i have replied with..."Already done 10 months back" I remember one time I got a 2 page list of questions from infosec about the network and over 70% of it I'd say didn't even make sense. They love a buzzword as I say, "we need to protect from DDoS attacks", so i sometimes reply with, "okay, how do we do that?". To which they have come back with responses like "better encryption", "better firewall rules", to which i raise my eyebrows and think..."you get paid to say things like that?" I sometimes as how and what does that mean then?, with no actual response there. I usually just reply with things like, we control the per client embryonic connections for incoming connections and our content filter and database is regularly updated and configured. To which they nod their heads and walk off. I swear they remind me of those in school or university were they join your group for a project, do 5% of the work and get the A grade at the end haha. It turned into a bit of a rant in the end but I wondered what other peoples thoughts were on the topic to?



No comments:

Post a Comment