Yes, Virginia, InfoSec *IS* an immature field
“Any field that’s dominated by its product and service vendors is an immature field.
Products can typically solve a narrow problem, but if you lead the security function at a large organization, narrow problems are rare. Problems are connected to other problems and surrounded by all the fun issues of ownership and stewardship and cooperation and accounting that make our lives rich and rewarding. (You may detect a tiny hint of sarcasm here, although it’s mixed with a larger portion of sincerity.)
Think of IT…er, management information systems…er, data processing back when it was all Big Blue over SNA. Costs were high and innovation was relatively slow. When the CIO voice became prominent—a business person running the IT shop based on the needs of the business, not the availability of whatever the vendors decided to put out—that’s when IT started to enable and contribute to systemic change and improvement.”
Amen brother.
http://www.csoonline.com/article/564963/Listening_In
