LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-12-2007, 08:15 PM   #1
packetsmacker
Member
 
Registered: Jun 2006
Posts: 68

Rep: Reputation: 15
General security question


I have a general security question. Its not related to any OS but about the security field. I would like to know the following.

Whats it like? What is a typical day like?

How did you get your job?

What is the best way to get into the field?

I was told by the head of security of the University I worked for that the security guy has all the responsibility but none of the power. He made it sound like he could recommend a policy that the higher ups don't want to enforced. So it doesn't get enforced. If that is the case I think I will stick with being an admin. Any help you all can provide would be great.
 
Old 03-12-2007, 09:05 PM   #2
macemoneta
Senior Member
 
Registered: Jan 2005
Location: Manalapan, NJ
Distribution: Fedora x86 and x86_64, Debian PPC and ARM, Android
Posts: 4,593
Blog Entries: 2

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
Every company is somewhat different, but what you describe is generally the case. Security is almost like hardware to a system admin. It has costs associated for the company. Just as you have to get approval to purchase items that exceed some value, security practices need approval because they cost the company time and/or money. The security guy's job is not to assume risk on behalf of the company, but rather to identify issues and determine if correcting them is cost effective (like creating a proposal for a hardware upgrade). Where a correction isn't cost effective, a risk mitigation strategy needs to be developed.

In both cases (admin/security), a better knowledge of the business is very useful. The more you understand the realities of cost/benefit/risk to the organization, and the better you document the practices, procedures and issues, the more your executives will trust your recommendations. At some point, that trust can translate to responsibility - you get to make the decision, without approval. At that point, your documentation with clear and concise communication becomes more important. It covers you when things go bad (and they will).
 
Old 03-13-2007, 05:20 PM   #3
packetsmacker
Member
 
Registered: Jun 2006
Posts: 68

Original Poster
Rep: Reputation: 15
Thanks for the reply.

So you are saying some type of business degree/experience would help me get in the field. I have a BS in Information Engineering. I was thinking of a MBA. I would like to do penetration testing but I think that is a rare job.
 
Old 03-13-2007, 05:41 PM   #4
macemoneta
Senior Member
 
Registered: Jan 2005
Location: Manalapan, NJ
Distribution: Fedora x86 and x86_64, Debian PPC and ARM, Android
Posts: 4,593
Blog Entries: 2

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
Whether an MBA is useful depends on your company and you as an individual. The issues that drive your business are not that hard to understand. Look beyond the scope of your job, and understand the jobs of those around you.

If your company allows it, rotate through as many positions as you can. Make sure you have up-front agreements on time frames; you don't want to be dead-ended in a role you don't want. Tier 1/2/3 support, project management, team leader - as many in your surrounding areas as feasible. The more exposure you have, the more you understand, the more you see. And more importantly, the more you are seen.

When you decide to rotate into security (or any other position), you will have the support, trust and respect of those in the surrounding areas. You will be able to make better decisions, because you will better understand the impacts of those decisions. You also become a very valuable employee.

It's not for everyone. Most people are happy with collecting their paycheck, and doing their thing. To me, work was 33-60% of my life; I aimed to make it as rewarding as possible.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about vsftpd security (or just ftp in general) scorbett Linux - Security 8 03-31-2006 04:56 PM
General wireless security question zba78 Linux - Wireless Networking 3 03-17-2006 03:33 PM
general security une Linux - Security 3 05-02-2005 08:08 AM
General Security ajbrouwe Linux - Security 3 07-14-2004 03:02 PM
Security in general NSKL Linux - Security 1 11-02-2002 01:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:10 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration