Considering Ethics for Security Teams
Have you ever been asked to do something at work that made you uncomfortable or went against your values? Not any Weinstein antics, but things that were considered part of your legitimate job? For many of us handling vulnerabilities, the primary discussion is where do we stand on coordinated/full disclosure. But there is a lot more to consider. Where are the lines? Who decides? What if you don’t agree? FIRST (Forum of Incident Response and Security Teams) is creating a code of ethics that security teams can adopt or use as a template to create their own. It can be used as a framework to think about how situations “should” be handled in incident response before it arises. This talk will discuss some of the overarching issues we face as an industry and how a framework like this can help.