How Not to Hire an Information Security Officer Who's on Parole

After learning that HR "forgot" to do a background check on a security staffer with a felony record, a leader reexamines his organization's policies

» View Article

READER FEEDBACK
Preview
Mike Kilroy
Wed, 2008-04-30 22:08

FYI, (ISC)2 recently released a hiring guide to the information security profession:

https://www.isc2.org/Documents/HiringGuide/HiringGuide08.pdf

They also have a resource page for HR people: https://www.isc2.org/cgi-bin/hiring_guide.cgi

reply
Jimi Hendricks
Thu, 2008-05-01 13:39

It would be interesting to follow up on situations where the "risks" were hired and performed long enough to see if they were statistically more risky than "non-risks". Most of the detetected problems were by people who would have passed security checks.
It may not be reasonable to assume that all criminals are "addicted" and thus a significantly greater risk. In fact, I would argue that knowing that "risky people" are present instills a discipline that aids prevention and discovery.

reply
Glen Matteson
Thu, 2008-05-01 15:41

It just go to show on how the upper management feel about security. He's doing the job, let it go etc. A good Security Manager who is well verse in both the phyiscal and personal aspects of security would have pushed to have a back ground check done prior to hiring anyone with in his or her company. But as usual, upper menagement were just trying to cover up what should have been done in the first place.

reply
Michael Dickey
Fri, 2008-05-02 13:39

All of your "hiring horror" examples have nothing to do with hiring practices or background checks and none would have been prevented by them.

I'm further not sure what an "update" background check is. Does their background change? Either this could be eliminated with a proper procedure up front by HR staff, or you might mean a psychological evaluation every few years. I'm not sure what the value that would be. Anything else like being on top of whether they've been arrested outside of work should be in the manager's realm of responsibilities.

I do like the point of this article, however. Have hiring practices and make sure they get followed! Unfortunately, this can only go so far. Almost all organizations are economically biased and I think all of them will eventually accept a risk if they can't properly fill a position otherwise or if he is adding value to the position.

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.