All you have to do to pretend to do a good job is to listen to the manager and the director and make your patch compliance numbers by manually making them up, and entering them into a manually made up website that is used to falsely report your patch compliance to meet or exceed the levels that are reported to the CISO....also known as Security Theater! Lol...I bet they did this at Equifax too. False sense of security for leadership, raises and promotions everywhere, but then the news story breaks that you knew you were purposely reporting false numbers to deceive leadership, stockholders, and the public.
9 replies (most recent on top)
When Intel pays market rate for qualified candidates
When will these fake security folks get a clue?
That's why every company should use the failsafe method of Trust BUT Verify! Trust your people, but view the raw data to validate that your trust is not being misused. The biggest failure of most security patching and scanning teams is that they do not look at or resolve the authentication reports. If you don't have the right credentials setup on every box to scan, you get bad results like not seeing patch levels, of not identifying rogue assets, and seeing the wrong OS on these boxes so you don't put them in the right compliance reports. Usually these get pulled out of the reports so the numbers look good.
I heard they pulled everything off of the report that was too hard to be patched, to make their numbers look good. I wonder if that is what the equifax folks did. You are only as weak as your weakest link, it only takes one server to compromise everything. Their CIO and CISO learned that the hard way. I sure hope this company's CISO and CIO understands that and gets this Failed Director and failed manager out before a breach can happen instead of losing their own jobs all due to an infosec ops patch team going rogue to make impossible compliance numbers that manager and director in their incompetent wisdom made up.
This is one of the many reasons why having Intel on your resume is a boat anchor.
Intel = do not hire
Be worried should your social security and personal details get compromised.
Couple that with non-tech and unqualified people from around the company with their job at risk and them at risk of layoff - getting brought into that Security to do security work. Any random person can right now get hired into the Security group.
Intel is more insecure than ever before.
Unfortunately for Intel everything said so far in this thread is true. Very sad condition of Intel and it is going to get a lot worse as Intel's gross revenue and gross margins begin to decline.
I've had self eviews that the manager was too lazy to even correct my spelling and grammar errors LOL