Building a Better Mousetrap: The Problem of Information Security Professional Organizations
I've been talking about the deficiencies in information security organizations for years. I've had board experience and other involvement with several such organizations and, let me tell you, it was an interesting learning experience.
I would like us all to do better and emulate professional organizations like the following:
What deficieicies am I talking about?
I'm talking about the excessive amount of vendor pitches. I'm talking about loads of ego and rockstar syndromes. I'm talking about overselling certifications and frameworks first and providing resources to forward the community second or not at all. I'm talking about not being a sales organization.
The best community moments that I've had have often been informal, friendly, and in the spirit of sharing information and comradery. That's what I would like to focus on and hear from you about.
What are your favorite aspects of community events? What have been some of the best moments of peer involvement that would not have occured without an event or organization bringing you together?
Are you a fan of:
- OWASP
- DatalossDB
- Toorcon
- CitySec
- Security B-Sides
- CCC
- Ignite
- Barcamp
- or others?
What is your favorite aspect(s)? What makes them valuable to you? How can we add to their efforts?
I'm not looking to start just another local chapter, but I want to provide resources for the global information security community regardless of their physical location. I want it to be easily accessible. I want to enable an open forum, not push people away. We need way more of that.
Will you join me?
If you are willing, I'm collecting data toward these ends. Information will be viewable only by me, Ian Gorrie, and destroyed after this exercise is complete.
Thanks for reading. I very much look forward to your comments and feedback.

The economic argument is getting worse (Score:3, Informative)