Job Postings and Too Much Information?
On a lark I decided to look at some security job postings, no not to look for a job but rather to look at what type of information is included in those postings. I had something hit me today that organizations looking to hire security professionals tend to place quite a bit of information in their job postings that could lead one to deduce what type of security applications, controls and countermeasures they have in place. When I was in the Air Force we called this Essential Elements of Friendly Information or EEFIs.
EEFIs themselves weren’t classified information, but with enough minor detail from multiple communications or, in this case, multiple web postings an adversary could determine some mission critical information.
Back to point, is it necessary to post specific information such as the below examples in job postings?
“Specific technical skill sets include: Anti-Virus (Symantec), Network Monitoring (Security, SecurFusion), IDS (SNORT, ISS), Vulnerability Assessment (Nessus, NMAP).”
Another posted required technical knowledge with Cisco PIX and TippingPoint IPS.
Yet another, for a public utility, requested knowledge with Firewall-1
These are just three examples that I found doing a quick search, I’m sure there are plenty more.
I realize that many of these are posted by staffing agencies so that it’s a bit difficult to pin point the specific company, but still is specific security technology too much to post in a job listing? I realize that, as a hiring employer, you don’t want to get inundated with resumes but on the other hand, as a potential attacker could this information be useful to me?
Comments
Leave a Reply
Ed Mahoney on 12.09.2009
I noted this years ago. I used inference – not for hacking – but to better understand industry trends. It was apparent over 10 years ago that everyone was migrating from Novell to NT because they said so in the classifieds. I sold my Novell stock and got certified on NT. From a recon perspective, HR is the weak link.
Tweets that mention Job Postings and Too Much Information? : Cassandra Security -- Topsy.com on 12.09.2009
[...] This post was mentioned on Twitter by jonamato, Cassandra Security. Cassandra Security said: New Blog Post: Job Postings and Too Much Information? http://cassandrasecurity.com/?p=926 [...]
Ken Beames on 12.16.2009
Great points. Unfortunately, posting the specific skills requirements has not yielded more focused and qualified candidates.
-Ken.