How to Suck at Information Security, from SANS.org
How to Suck at Information Security Some of my favorites are: * Require your users to change passwords too frequently. * Expect your users to remember passwords without writing them down. * Don’t cross-train the IT and security staff. * Expect end-users to forgo convenience in place of security. * Lock down the infrastructure so…