Maybe I too was impatient with the outcome. But I used to sit inside orgs and study their code and suggest things. It’s weird to think back on that stuff. I found a misspelled line in QRadar that was causing crashes when specific if/when things happened. Solved it in about 6 hours without any formal knowledge of the mess. But it made sense. (Hint left off U in user)
@IAMERICAbooted Ha. I hear this. Leadership mostly is making friends and taking wins based solely on reactive status items that would otherwise be negligible otherwise.
It’s interesting. My level of knowledge and vast depths of stuff I know is often misunderstood or unknown to most. Some chuckle, some are offended if you will, but I was mostly shocked people just didn’t know what others or themselves claim, or how folks can be “the expert”. To me, the expert has the whole system in and out understood. I live alone mostly on how many improper, wrong, and outright blatant misinformation people say, and because nobody measures, checks, validates or asks… it will just continue. I cannot do what I’m hired to do… if ever. But I’m the random tool you use for that odd job. Believe me when I say, I understand
Impossible to not agree enough. The other things are drive/desire and thinking beyond the problem and not a lifecycle.
E.g., provide vuln dashboard. Ok, what are steps to have exclusion for risk, where is the standard, what is a fluid and easy to use exclusion process? Where are you putting these documents and how are they communicated?