From the editor's desk: Maybe security should STTFS

Issue 2 2021 News & Events

The IT industry has an acronym, RTFM, Read the Manual; you’ll notice I left the F out. The same can be said for the security industry, but a recent experience has shown me that both industries, even as they converge in many areas, need to not only RTFM, but also STTFS.


Andrew Seldon.

The polite version of STTFS is Stick To The Standards. This applies to any and every part of an installation. In the electrical industry there are set standards to ensure safety and reliability. If you decide to rewire your house according to your own clever ideas, you will be in for a nasty shock when you have to get a clearance certificate in order to sell the property. The same applies to electric fences; you need a certificate of compliance for your fence if you want to sell your house.

All the rest of it is up for grabs, it seems, because there is nobody with a big stick insisting on standards and compliance. There are no regulations for installing a network (unless you use licenced frequencies for wireless or want to lay cables across public roads), but there are standards and best practices. The same applies when installing access control, alarms and surveillance cameras.

The experience I had was of someone being clever and installing things according to his idea of what was right, or maybe he was just lazy. On the other hand, perhaps he was looking to secure a long-term job for himself since nobody else could replace him – or so he thought.

Replacing the individual was indeed a challenge as the new ‘guru’ had to do a lot of probing and testing and guessing to find out how things were done (there was, naturally, no documentation). Long hours and frustration was the order of the day. In addition, the company itself faced large costs in new kit to replace the outdated and badly installed and configured equipment (as well as expensive experts to reconfigure and fiddle with stuff to get it up to scratch).

The lesson to learn is that standards and best practices are there for a number of reasons. One of those is longevity and maintainability. If your guru vanishes, someone who understands these standards can take over with the minimum of fuss; or if your systems integrator loses the plot, another can be brought in fairly easily. In both cases there will still be a learning curve, but standardising on accepted standards and best practices will reduce it significantly, as well as the frustration and costs involved in detective work.

Even if you are buying the latest and greatest new AI thingamabob that has no standards associated with it, the cameras, networks, servers and management platforms do. If your guru or SI isn’t willing to document their installation and adhere to standards, perhaps you should insist they STTFS or show them out of that age-old standard, the door.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SABRIC appoints Andre Wentzel as interim CEO
News & Events Financial (Industry) Associations
The South African Banking Risk Information Centre (SABRIC) has announced the appointment of Andre Wentzel as interim chief executive officer, effective immediately.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Paxton cuts emissions by over a third
Paxton News & Events
Paxton has announced a significant reduction in its carbon footprint, cutting emissions by 961 tonnes of CO2e in its 2023 second reporting year.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Nice unveils MyNice Smartgo
News & Events Access Control & Identity Management
Nice SA has announced the release of MyNice Smartgo, a compact access automation solution, designed specifically for the South African market, combining an easy-to-install device with a user-friendly smartphone application.friendly smartphone application.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
SA businesses embrace GenAI, but strategy and skills lag
News & Events AI & Data Analytics
South African enterprises are rapidly integrating Generative AI (GenAI) into their operations, but most are doing so without formal strategies, dedicated leadership, or the infrastructure required to maximise value and minimise risk.

Read more...
Continuous security optimisation.
News & Events Information Security
Cymulate has announced its partnership with SentinelOne, a threat exposure validation and AI-powered cybersecurity platform. The collaboration delivers self-healing endpoint security that empowers businesses to increase protection for every endpoint on their network.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.