Security so(m)bering

There’s this discussion going down on the merits of privacy versus security. Whether the one is part of the other, or the other way around, or both. Whereas the smarts are with considering privacy enhanced by good confidentiality settings ’cause they see that privacy is an issue of higher (abstraction) order than mere confi; achieved by it but only as infosec are the bricks and mortar when all you wanted is not bricks or so but a wall.
Through which you may reflect on compliance in infosec. Because hardly ever, is that taken to include compliance with the principles and business objectives and conditions that include being sparse with hinder to the business. Really, those that truly set only guiding rails not enforcement rails, are the unicorns of the trade. No, not those unicorns, those are just frauds anyway.
You may try to do better; really. It starts with risk … when properly applied, you would not get the remarks about ‘why, it has never happened to us before / what are the odds?’ but might even get better support for some slightly hindering process changes and better (but less end user detectable) ‘infra’ i.e., everything under the users’ level of visibility.
So, I’m not sombering or if, about the eager beaver pervasive prevalence. Because sobering up, wising up, may win the day and may be due…

We shouldn’t somber too much… Isn’t this a perfect opportunity to finally demonstrate how we do (… can …) link up information security to real business issues at the highest GRC levels. Since we shouldn’t be passive, and leave ‘privacy’ to be taken over by lawyers jumping into the current Privacy Officer void. Since we can translate all the operational and tactical work that we do on privacy, all the way up to strategic levels and still be very concrete. And not have to wait till ill-understandable “guidelines” (shackles) keep us from achieving something.
No more wannabe whining about ‘deserving’ a seat at the Board table or at least be heard; not asking to be allowed but matter-of-factly showing ‘Done.’ … if, not when, you did informtion security right all the way…

Just like that:

[“Na na nanana can’t hear you!”; Porto]

Miss Quote: Your way. Or ..?

In the series of unfortunate misquotes, a famous one:

Anything that can go wrong, will (Murphy)

As a secondary quote from somewhere:
But Edward Murphy did not say this. What he most likely did say is something along the lines of:

‘If there’s more than one way to do a job, and one of those ways will result in disaster, then somebody will do it that way’.

Which only by you with the way you do things, does indeed result in disaster, without fail. So, if you use the misquote, you should add “when I do it”…?

That was a short and easy one … so, for you:
DSCN7697
[You picked its current spot; deep into the harbour…; Baltimore]

De nieuwe KvK-registratie

Voor velen is het een klusje dat lastig is, maar er nu eenmaal bijhoort als onderdeel van ‘being in business’.
De registratie bij de Kamer van Koophandel. De basics, bij de enthousiaste start van bijvoorbeeld een zelfstandig bestaan. Het onderhoud, bij wisselingen in het verenigingsbestuur — en dan blijkt de KvK dermate relevant, dat men nog een natte handtekening vereist maar dan wel in het bekende veel te kleine rechthoekje te plaatsen waardoor de gezette handtekening welhaast per definitie niet klopt…! Hoe diep in het vorige millennium kan je achtergebleven zijn; dit toont wel aan dat de KvK welhaast niet nuttig meer kan zijn…

Maar nu is er in tijden van ‘cyber’ (#ditchcyber!) een alternatief of eerder, een vergelijkbare registratie: Bij de AP.
Jawel, de Autoriteit Persoonsgegevens, zo genoemd omdat de verwarring met het begrip ‘privacy’ nog niet groot genoeg was wellicht, en hernoemd om weer een decennium opstarttijd te geven voordat effectiviteit kan worden verwacht en alsdan weer een nieuwe tijd aangebroken is die vraagt om een ‘andere’ instantie ..?
Want we hebben immers de Wet meldplicht datalekken… Met 700 registraties in de eerste twee maanden (rekening houdend met een volle eerste maand nieuwjaarsborrels, dus een week of vier) is wel duidelijk dat het een kwestie is van (aan)melden en verder gelukkig niets — tenzij men pech heeft niet politiek relevant te zijn en ‘dus’ najaagbaar …

Ach, overheid; leuker kunnen ze het niet maken, wel onmogelijker…?
DSCN1834
[En daar komt nou ook niet echt tegenwind vandaan…]

Yup, there it is …

… What took us (?) so long …?

Hybrid war

Yes, the phrase we all were waiting for, or might have predicted but hardly anyone did. But now, out there for all the FUD and fear mongering (to profit from ..!). May this be the avenue of submersion of cyber (#ditchcyber !), like a U-boat trolling and unexpectedly blowing you out of the water?
What will be, will be. Grab the money trucks!

On a side (?) note:
DSCN7602
[Transport for the consultants /-cy fees for you, required to tackle it all; Baltimore]

Mayans leaving the US

Would anyone have a pointer to the research that compares the Mayans’ demise with latter-day developments in the first world ..?

As one hears not too much lately, about that grand theory about the sudden disappearance of the Maya culture that suggested that one-percenter total disconnect with the other 99%, lead to the latter leaving the, no more capable of sustaining themselves in the least, überbureaucrats to litterally starve in their palaces.

Which might very well happen if the Powers That Be, e.g., the 1% of business and congress and the sycophants/lobbyists around those, would continue their disconnect now so amply demonstrated in, e.g., primaries on both sides of some spectrum (both actually being far right, maybe?), to name just an acute symptom.

So, are there any anthropologists out there studying that odd primitive (here, without the ”…) tribe of white men (sometimes, very sometimes, caught in the body of technically a woman) and comparing the parallells with said sad Untergang des Maya-landes ..?

Even when I wouldn’t know what the results could be. Do count on the ‘Now is different’ error of which the size cannot be overestimated. But also, very maybe, detect the slightest of pointers towards betterment of current-day societies. And ways to make us see the latter their value, hopefully — hope being what’s left when arguments are lacking.

On the positive side:
DSCN9971
[Similar not same: small-time onepercenterville now a tourist attraction (hotel); Gabbiano, Toscane]

Miss Quotes: Free Hegel

The quotes, of motivational nature or other, that you meet every time again — but aren’t, since they are garbled versions of the original. And the original had much more profound wisdom, or was even true where the misquote isn’t.

Yet another one in a series, a rather old one:
There’s nothing sure in life except death and taxes.

… …

For one, “The only thing you can be sure of, so the saying goes, are death and taxes — but don’t be too sure about death.” (Joseph Strout) — before but on the Kurzweillian strain of thought (more on that elsewhere on this blog) that ‘humans’ may leave their biological medium (‘substrate’) and live forever — probably on tape or 5″ floppy disks though that angle Ray discusses [satisfactory, for once] too. But whether Ray’s scenario turns out to be true (where would religion go …? Betraying his/his father’s roots?), or the Spinozaic or anthropomorphic deity would allow to be overruled in v1.1 of the Design, it would be short-sighted to take dying as inescapable.

For another, [skipping lazy evaluation of the And clause that would already render the quote a miss] David Graeber already proved that in the history of humanity, almost no-one ever paid taxes, the above is just an order by the receiving end put onto the paying end to suppress any even the slightest inkling of an idea for revolt. Whereas the Dutch started their war of independence officially because of an income tax levy of 10% — the outrage! and practice was ‘slightly’ different, very probably. So, no score here, either.

QED.

And the Hegel of the title: Search my earlier posts on that.
And:
DSC_0384
[This beauty however may not last forever ..? Bibliothèque Vanderbilt, Reims]

Without voice (left); a lot

Sometimes, one sees a recurrence of the remark that those who complain (loud(est)), shouldn’t for they have a good time by apparently standing to lose something but having more than enough, though possibly threatened, to be able to shout around and one should listen to the silent that have no voice by being too weak to raise it and hence need our attention and support much more.
So… which groups in society, of whatever slice or dice, do we hear complain (loudest) nowadays and have no ‘right’ to? Right, compared to the really, seriousy needy. And which groups don’t we hear from though we the String should hear from and listen to?

One need not have studied the Classics — though that may help a lot (as here / search ‘Oh, yeah?’) but many compense by being wise despite lack of formal education and others mistake themselves in the opposite due to the opposite — to see that in any devolved state of affairs in societies, since the Greeks and their philosophers’ ill understanding of the Too Far of Utopian visions taken too far, extremes (sic) of total egalitarianism in ‘democracy’ (quod non!) or absolutism commonly by some boor(s), there comes some time that balance must be brought back, from the extremes, with apparently inappropriate circumvention of the absolutes’ symptoms and have ring leaders that understand and modulate their mob rule to levels where truly, ‘government’ (whether official or not, the latter by filling in the blanks that totalitarian bureaucracy leaves; look ‘Southern Italy’ as a general pointer, not too literally) will start to defend the weak from the strong. [Hey a sudden period. But … clarity and brevity of sentences are quite perpendicular qualitative vectors!] As the strong will be able to look after their own interests per se already, and the weak have none to fence for them — but now will. Noblesse oblige.

So take care ..!
But either you knew this all already, sigh; or it’s pearls before you.

Leaving you with:
DSC_0242
[Belittle no one human, my friend; NY ..?]

Privvezee Shield

The fig leaf of the trade ..?
Probably will blow in the wind at the first whisper over 2Bft. E.g., through ‘misinterpretation’ of the rules and inherent incapacity to understand the Principles, by some vague fifth-line anonymous placeholder instructed to not understand, buried deep down in some TLA you may or may not have heard of.

And then, the wind cried Mary; landsliding into only the thinnest of lip service with a torrent (no double entendre intended) of factual breaches.

You’ll see… Plus:

DSCN7411
[A sub, appropriately, even if only in Baltimore…]

Top 10 things that interest you

Where the title is a total fake, just to get higher in the pop rankings. Of course. Because that’s what life is all about and a top five wouldn’t have done the trick.

Now then. On the subject of Roman decadence. Or not, because you’d not like discussions of US pre-elections in light of societal developments there. Still, the subject is interesting as it demonstrates again (after Argentina’s Peron age, and Italy’s B.rl.sc.n. age, and the dreadful general state of Duts politicks) that the ones aiming for democratic perfection, may by and large have arrived at the end game of the moral era. As in the link here and according the jeer of some ill-guided closed-minded utopian (isn’t he?) at the end regarding e.g., Greenpeace but of course taking not broad a scope enough.

To rest my case, The similarities are striking including the varying prolongment of the demise…

And:
DSCN8538
[Devil’s detail ..?]

Vindication …

With due respect, but vindication is a beautiful thing…
As I had delivered a lecture over five years on all the places that risk management of the Basel II/II style, using quants and all to model (an übercomplex combination of scores of) human behaviour thus sublimating one’s model errors and one’s misunderstanding of how the world turns, not even mentioning the risk of the 15.5 risk; necessarily (if you’d had got It) speculative about what’s next, the evaluation was heaviliy tilted from quite (UK style) positive to mediocre by one bad review, that had as only comment “not based in evidence”. See the latest pres’s in my LinkedIn profile; without much by way of speaker notes, the ones on e.g., Blind Alley et al. can be readily understood qua intent.
Recently then, finally, this arrived. Maybe spinning off in an adjacent direction; veering off or running in parallel? But definitely touching the sore spot.
To the point where the dish is sweetest served cold.
But hey, would have liked all the business (and ~travel…) opportunities that could’ve been…

Now, let’s all go study Basel IV’s methodology and learn (e.g., as in the above-linked article). Maybe there is a future for risk management. Even if not as a separate discipline; see my posts of management-in-general. Plus:
000003 (8)
[Once was my ‘work’ location; worth re-pursuing Trois Islets, Martinique]

Maverisk / Étoiles du Nord