DEV Community

Cover image for The Tragedy of the Clean-Handed Auditor
Ben Link
Ben Link

Posted on

The Tragedy of the Clean-Handed Auditor

"I could save them if they'd only listen..."

Hey, you. Yeah, you: the compliance or governance person who stumbled across this blog. Who isn't part of the "usual" audience for an Adventure of Blink, but somehow the algorithms aligned to serve this up to you today. Today's post is just for you. I'm not going to speak developer-speak today... it's just you and me, chatting in a safe space.

I want you to know that I SEE YOU.

I know your pain. I know that you're doing everything you can to keep the company safe and secure and protected. That you carry the burden of dealing with those auditors. That their pedantry and desire to find fault shapes how you have to approach everything in the organization.

I know that you're fighting the Good Fight. You want the organization to succeed, and keeping those nitpicky auditors away is how you can help us reach that success.

I want that too.

Let's talk about the Disconnect

You know it's there. I know it's there. We haven't seen eye-to-eye for a long time on how to achieve safety and compliance while still delivering for our customers.

Your perspective is that I'm a cowboy coder who hates all forms of authority; I'm reckless and impatient and generally unconcerned with safety as long as I can sling things into production.

My perspective is that you're a Vogon, who wouldn’t even lift a finger to save your own grandmother from the Ravenous Bugblatter Beast of Traal without orders signed in triplicate, sent in, sent back, queried, lost, found, subjected to public inquiry, lost again, and finally buried in soft peat for three months and recycled as firelighters. (Before you get offended by this, take a minute to realize that it's hyperbole... Look it up 😉. It's also a quote from Douglas Adams, and if you didn't recognize it you need to read "The Hitchhiker's Guide to the Galaxy", you uncultured swine. 🐷)

There. We got that out of the way. Let's talk about the Tragedy of the Clean-Handed Auditor.

What You Do

Your job, as you would generally describe it, is to secure the environment against threats. You do this by relying on the latest Security Audit Controls, published by highly respected bodies who have declared themselves the standard for, well... standards.

You spend your days reviewing these Controls and mapping them to documented Processes within the organization. The general thinking is that if we can adequately explain how our Processes meet all of these Controls, we will be certified "Secure and Compliant" to these bodies' Official Standards.

It's a fine goal, to be sure.

Today, though, I'm here to tell you why you've got it all wrong.

Screenshots Don't Create Security

"Clean-Handed" Auditors have fallen in love with a proxy for reality, to the point of completely ignoring that reality.

Imagine being on an airplane where the pilot spends the whole flight looking at his checklist instead of, well... you know, flying the plane.

Your screenshot of a settings page isn't a secure configuration. It's not "proof" of anything, except that I know what settings page you're talking about. And no matter how complex your documentation process is, that screenshot isn't the configuration... it's just a moment in time, something whose expiration date is the second after the timestamp on the image.

Here's the kicker though: getting you that screenshot (and a bunch more, let's face it you're not going to just ask me for one, are you? 😏) is going to eat into a significant portion of my workday. I don't have time to make my system secure because I'm busy "proving" it with screenshots and signed PDFs... you know, the ones that we talked about in the last paragraph that DON'T actually prove anything!

Your developer teams use the term "Security Theater" for this. We know it isn't actually making us secure, but we have to do it to satisfy you. It's a major part of why we're so disconnected.

Your Clean Hands Are Problematic

There's a better-than-50% chance that you would say something like this:

  • "I'm not a developer"
  • "I'm not super-technical"
  • "I focus on the Process, not the Implementation"

I'm not suggesting that you have to become a full-time developer. But I DO think you need to realize that refusing to touch the work is causing you to fail at the very thing you're trying hardest to achieve: Securing the System.

Stay With Me, We're Going Somewhere With This

Friend... I don't blame you. The system taught you that it was ok to do it this way. It was designed by people who didn't know the pain they were causing, either.

I think there's a better way. I think we can find it together.

And I'm asking you to follow along as we figure out how. Next week we're going to talk about the beginning of that "how", and then set ourselves up with a challenge that leads us right into Season 6.

See you next week, my friend. We're about to change the world!

Top comments (0)