SAI HONIG
IS IT TIME FOR A PERSONAL C-I-A TRIAD? by Sai Honig, Engagement Security Consultant at Amazon Web Services
According to the Merriam-Webster dictionary
just started getting a group of similar professional
accountability is “an obligation or willingness to
women together. She expressed frustration about one
accept responsibility or to account for one’s actions.”
woman to whom she had given a ticket to a capture the flag (CTF) event. The woman did not show up
As information security professionals we naturally
and did not respond after the event. I suggested to
hold ourselves accountable for ensuring the systems
my contact that, instead of complaining to me about
and data under our care are kept secure. We are
someone I did not know, she should dedicate no
constantly reminded of the C-I-A triad (see diagram
further time or thought to the no-show and not invite
on the next page).
her to any future events.
How are we doing with our accountability to each
This woman who reached out to me had been
other in information security? I have had reason to
inspired by what she had read about New Zealand
ask that question for myself. I have read comments
Network for Women in Security (NZNWS). I told her
where individuals and organisations have been
that, over the last three years, my fellow co-founder
publicly abused. This goes above sharing information
Tash Bettridge and I had heard from many women,
about doing better. It is outright abuse. Our profession
and men, who had said they wanted to assist with
is stressful enough without the additional stress that
NZNWS. However, when we asked them to join us, we
results from personal attacks.
were met with silence. We have even been recipients of negative comments. Rather than complain about
I suggest creating your own personal C-I-A triad, as I
those who would ignore us, or even try to thwart
have done and as I will explain later in this article.
us, the two of us moved forward with our own limited resources.
Recently, I had a conversation with a woman who
70
reached out to me about setting up a network for
Eventually others saw what we were trying to
women in information security in her country. She had
do and joined us. We now have an active crew
W O M E N I N S E C U R I T Y M A G A Z I N E
M A R C H • A P R I L 2023