Is Your Definition of Security Holding You Back?
Hunched forward in an effort to find comfort in old, wooden chairs gathered around a whiteboard in an oversized conference room, the ten people sitting before me each clutched a single sheet of white paper in one hand, a pen in the other.
Mon, February 13, 2012
CSO — Hunched forward in an effort to find comfort in old, wooden chairs gathered around a whiteboard in an oversized conference room, the ten people sitting before me each clutched a single sheet of white paper in one hand, a pen in the other.
Nervously, they looked to me for direction, wondering what on earth I was about to ask them to do.
"Take 5 minutes and write down your definition of the word security, " I asked.
(Tip: might be interesting to stop reading, take a moment, and do the same)
[Three reasons why asking risky questions reduces risk]
Nervousness instantly changed to comfort, for I asked a simple question everyone knew the answer to. Each of the participants quickly started to scribble their definition on the paper.
About a minute later, I noticed a few people scratching out words, phrases and, in some cases, the entire definition.
Three minutes in, people were still writing, pausing for a moment to think, draw an arrow or two, scratch out a concept and then scribble again.
At the end of the five minutes, I asked the members of this team to share not only their definitions, but also their reflection on the exercise. More interesting than the actual shared definitions was the fact that by asking 10 security professionals to define security, I got 15 responses!
I've repeated this challenge multiple times and generally get more definitions than the number of people.
This happens because when first presented with information, a task or a concept familiar to use, we readily presume understanding.
The moment we need to translate a loosely held notion in our minds to a precisely defined meaning, we realize that context matters and the definition might change.
Test it out on yourself and on your team.
Why it matters
To be an effective security professional requires an understanding of risk, risk tolerance, threats, business, and a multitude of other essential topics. Under the moniker of "security," lies a large potential of technologies, processes, and services we offer to those we serve in an effort to reduce or maintain risk at reasonable, acceptable levels.
Consider the responses people offer when we introduce ourselves as security professionals? Over the last two decades of testing and changing how to explain what we do, the responses have tended to focus on what the person I was talking to understood. If they considered security a firewall, that's what they thought I did. If it meant a bodyguard, I must be in personal protection.


