Since the spring HOUG (Hungarian Oracle User Group) conference was, much to my regret, cancelled — where, incidentally, I myself was supposed to be among the speakers — the autumn event, fortunately, did take place.
In general, I have mixed feelings about professional conferences, especially seeing the current flood of online presentations, of which there's more than one every single day.
On the one hand, it's good that you don't have to travel everywhere, look for parking, sit through an entire day even if a given presentation is completely irrelevant to you. I'm also glad that there's plenty of choice.
On the other hand, this way I'm much less able to focus on the speaker, on the topic, and one's attention involuntarily starts to wander along the way, so the conference ends up being nothing more than background noise.
But what I miss most is the opportunity for personal networking, although, as I've experienced, introverted IT people tend to be pretty weak at this and usually end up nibbling on the same pastries alongside whoever they came with from the same company.
As for the content, I always find it refreshing when presentations are tied to a specific company, case, or set of problems and their solutions, as opposed to just showcasing general technological novelties. Because our job is, in theory, about solving problems.
Fortunately, the HOUG conference also had presentations that touched on practical questions.
Ádám Nagy heads the information security department at K&H Bank, and spoke about cloud-based data warehouses, and about the security issues of data warehouses in general, in a very down-to-earth, human way.
My general experience regarding the attitude of the departments responsible for IT security at multinational companies can be summed up in two words: "It can't be done."
After all, if we don't do anything new, then it's not dangerous. Perhaps this approach is similar to that of an employee who wants to spend all 40 years of their career at a single company. We feel that this seems safe, but since the odds of it are small, it really isn't.
The data warehouse is a sensitive area anyway. The saying "everyone gets only as much access as is minimally necessary for their job" can't be entirely true either, because then how would data mining even be possible? I can't think of a better word right now, but the various models can turn out better the more, and the more varied, data a given user has permission to rely on.
That's why it's important to classify data into different levels, which can be at a "super, super" security level, at the level of "business data," or data that's public for everyone.
Other presentations covered cloud-based data warehouses, whose services are expanding at an incredible pace. Building and operating such a tool on an on-premise basis, besides being expensive, is almost impossible — everything is evolving so fast.
So the "it can't be done" stance of information security should shift toward "let's take a look" and then toward "let's do it properly," because besides the fact that the world is running past us, the main question isn't really whether the data is in the cloud or in a room in the basement, but much more the human factor, which should be paid attention to — through training and education, for example.
Because if someone is still at the point of writing their password on a Post-it and sticking it to the monitor, then it doesn't matter how much we cling to "tried and tested" IT structures — we won't get anywhere with them.
Link: https://houg.hu/


