Also, as noted in the comments, it sets a bad precedent for people coming forward reporting issues.
Also, as noted in the comments, it sets a bad precedent for people coming forward reporting issues.
I think the key phrase you are missing which is repeated many places in the timeline is “Engineering was not consulted”. His failure wasn’t that he doesn’t know the entire system, it was that he kept engineering in the dark, “investigated” on his own, and made conclusions to disregard the persistent researcher who kept banging at the door saying “there is an issue” despite him disregarding it again and again, notably without consulting engineering.
You don’t need to know the entire system as CISO, but you certainly do need to know that you don’t know the entire system as CISO. This wasn’t an institutional failure, it was a personal failure at a very high level.
I’m not arguing that the guy had to resign, merely pointing out that the narrative used to argue against his resignation is flawed.
accountability at the top is a good thing
Bugs happen, and he's doing exactly what's expected of a leader in this situation. Anyone who thinks "this incident is personally my fault because I didn't read every line of code the devs who work for me wrote, and for this dishonor I am now unfit to lead" is a sane reaction to these events is not living the blameless postmortem life.
Captains used to go down with their ships. In most organisations, this is no longer the case, because we lost all the captains willing to do so, without replacement.
Resigning when you fail to prevent an incident rarely helps, directly. But it's not something the power-hungry do, unless forced (and if they expect to be forced, they will try to cover things up). It rarely fails to win my respect. As a move in a social game, I suspect that the general strategy "resign when an unacceptable failure has occurred" makes things better, overall, even if it doesn't directly benefit the organisation you're leaving. (I'm not sure whether this applies when you don't expect that your replacement feels the same way about duty.)
You have much power, but little as well because every department claims security is the reason their projects are delayed - or if they move quickly and there is an issue, they point back at CISO.
that it were self initiated
* Does replacing the CISO actually make the system more secure? Presumably he had a lot of tribal knowledge built-up and who is going to know the system better than him?
* As systems get more and more complex, it's likely impossible for a single individual to truly understand and prevent these types of situations 100% of the time. It seems that any application that needs to be 100% secure (if that is even possible) has to be provably secure in a strict mathematical sense, which goes beyond individual culpability.
* Does shooting the person accountable actually encourage responsible disclosure or discourage it?
Wherever the bar is, it won't be 100%. That's why good leadership invests in the ability to respond well to mistakes that will inevitably be made.
This replacing the leadership is always the right response.
Counterintuitively, probably yes. Tone flows from the top down, and if you want to change the tone you need to start at the top. It's very difficult to try and build a coalition to change the system from underneath.
Presumably he had a lot of tribal knowledge built-up and who is going to know the system better than him?
Likely he has a lot of political influence and knowledge of the system and for lasting change all of that has to go. If it has gotten that bad it's no good and needs to be swept away.
Much of it at that level is NOT architecture and software discussions. You wouldn't think the job would be similar to lead counsel, but unfortunately a majority of a certain company's risk now a days is in that area.
Those processes and policies are set by someone.
From his resignation:
> This incident made me realize that I am no longer the person for this role.
Seems reasonable.
I also find it ironic to discourage this because of the precedent it sets. That’s making him responsible for things out of his control.
Honestly, I can understand that. I can respect it too. I can imagine the stress over that period of time being very high. Personal attacks, business attacks, mounting legal issues from business _partners_. We work in computers sitting on our ass. We are not used to these stressful events. This was probably Jermey's _stress test_ and he unfortunately broke.
I just hope he finds another gig or maybe starts up something on his own. I would probably follow him.
It usually happens when people up the ladder want to shrug off their responsibility completely. Loser mentality.
Don't condemn people until you have all the facts, which multiple reporters are working on figuring out right now.
Disagree entirely. Shit happens, and it’s important to accurately report things going on. Sure someone could interpret this as “we should fire the people who make mistakes” but I think it’s unrealistic to begin with and if it were to happen people would see through it.