Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

First, Can we stop pretending to be more intellectually honest by using “good” instead of “best” practices?

0
Posted

First, Can we stop pretending to be more intellectually honest by using “good” instead of “best” practices?

0

Despite the seeming rhetoric to the contrary a list of universally accepted “good” or “best” practices doesn’t exist. At best, practitioners use them similarly to what Justice Potter said about pornography – I can’t tell you what the best practices are, but I know one when I see one”. At worst, they are created on the fly to justify an ad-hoc risk analysis (playing cyber-cop) “best practices say you can’t do that, neener, neener, neener.” As this blog has mentioned before, the entire concept of “good practice” is simply a lazy man’s risk analysis. In as much as it would seem to be good and professional to the reader to do as Donn Parker suggests and hope that we could be standardized like accounting principles, the reality is that security is far too dynamic for that analogue to work (which is why I always find it odd that good practices are offered as a remedy by those who would suggest that risk analysis doesn’t work because attackers are “asymmetric”. I’m not sure this asymmetry is

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.