MichaelPeters.org

  • CRM
  • PMP
  • 0
  • 1
  • 2

MichaelPeters.org - Your Personal CXO, LLC

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

B.S. in Best Practices

0

By Michael Peters on January 3rd, 2011

Have you ever sat in a meeting with auditors or other third party professionals who will include the phrase “best practices” in their argument or report? I have no idea how many times security practitioners have tossed this phrase about to bolster their position. I’ve read that phrase countess times in articles published by reputable publications. Have you ever stopped to think of what that actually means? Best practices according to what authority? What is the source of power behind best practices I wonder? My observation thus far has been that this catch phrase is used by those “professionals” who are insecure in their position. To validate my point, I would encourage you to challenge or “question authority” the next time you are participating in some meeting and the designated expert tosses that phrase out. Ask that person to articulate the source or foundation of their statement. I suspect that you will discover, as I have, that the freshly minted MBA or certified professional snake oil salesperson will suddenly stammer and stumble. The explanation will suddenly turn into an exercise where they attempt to lull you into a comfortable “moving right along” dialog where they attempt to hang onto that authority you have given them. My advice to you is that keeping a mental red flag handy for that particular phrase and challenging the person who drops it will be beneficial. When you have a reputation of fact checking and demanding credibility from your professionals, you will get better explanations that are meaningful and worth the price you paid.

Share this:

  • Email
  • Print
  • Digg
  • Google +1
  • LinkedIn
  • Twitter
  • Tumblr
  • Pinterest
  • Reddit
  • StumbleUpon
  • Facebook
  • CXO, Uncategorized
  • Search

  • Your Personal CXO

  • The Security Trifecta

    Hire the experts to implement The Security Trifecta in your organization. Click for more information!

  • Louisville Metro InfoSec

    The Louisville Metro InfoSec is the premier ISSA information security conference!

  • External Services

  • Thousands of other great people can't be wrong! Enter your email address to subscribe to this blog. -

  • Affiliates

  • RSS SBN RSS

    • Secure Configurations for Firewalls, Routers, and Switches – Critical Control with an ROI!
    • Motive and motivation are the ONLY skills a real hacker needs
    • Gun Fight at the OK Corral
    • Senator’s wife lashes out at (probably) fake women chasing her man on Facebook
    • Red Dawn: Protecting small organizations from attacks
  • RSS The Register

    • Yahoo! joins! rivals! in! PRISM! data! request! admission!
    • Half of NASA's latest asteroid-chasing space rookies ARE WOMEN
    • O2 averts strike action over mass Capita outsourcing deal
    • Microsoft lures buy-curious vixens, corduroys with a cheap fondle
    • Drug gang hacks into Belgian seaport, cops seize TONNE of smack
  • Categories

    • Books
    • CXO
    • Featured
    • HORSE Project
    • HORSE Project V1
    • Kickback Cafe
    • Law
    • Lazarus Alliance
    • Life Learner
    • Obsolescence
    • Projects
    • Remember
    • Securing the C Level
    • Syndication
    • The Security Trifecta
    • Uncategorized
    • Your Personal CISO
  • Archives

    • March 2013
    • February 2013
    • January 2013
    • December 2012
    • November 2012
    • October 2012
    • September 2012
    • August 2012
    • July 2012
    • June 2012
    • May 2012
    • April 2012
    • March 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011
    • January 2011
    • December 2010
    • November 2010
    • September 2010
    • August 2010
    • July 2010
    • June 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • May 2008
    • April 2008
    • January 2008
    • December 2007
    • July 2007
    • June 2007
    • May 2007
  • Get the app!

    Your Personal CXO now on Android!

  • Get the app!

    The HORSE Project now on Android!

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

More on Your Personal CXO, LLC

  • EXTERNAL

    • AppHappening
    • CheckSavvy
    • Dynamic Clinical Systems
    • eLance
    • HORSE Project
    • Maprehend
    • Quest for Tech
  • Meta

    • Register
    • Log in
    • Entries RSS
  • Recent Posts

    • The Policy Machine
    • Top 1% Most Viewed LinkedIn Profile
    • Reasonable Duty of Care: Data Security and Privacy
    • Security Overlooked: Weathering the DDoS Storm
    • Please Vote for this blog!
  • Top Links

    • clouds (70)
    • No Title Given (57)
    • mba-mdp (47)
    • site (30)
    • peters-wgu-sbit-infosec (25)
    • CISSP-MDP-2013 (23)
    • An Introduction (21)
    • http://michaelpeters.org/?page_id=336 (21)
    • LinkedIn.com (19)
    • CMBA-MichaelPeters-2007 (17)

Copyright © 2013 MichaelPeters.org - MICHAELPETERS.ORG - Your Personal CXO, LLC

 
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.