Metadata

Opinion
Oct 26, 20064 mins

* A reminder of what this column is all about

In database theory, “metadata” refers to information about the data. Metadata include field descriptors, edit masks, record numbers, pointers, counters and so on.

Today I’d like to provide readers with some column metadata: information about the purpose and nature of this column. I am moved to do so in part because of recent correspondence from readers who have told me what to write and what not to write in the Security Strategies newsletter.

One reader objected to the inclusion of a comment in my article about voting machines: “Make your vote count: don’t let proprietary, secret software undermine what little democracy we still have left.” According to the reader, that sentence was overtly political and should not have been included in a newsletter about network security.

I avoid neither political topics nor political comments. Wasn’t that obvious simply from the topic – electronic voting machines?

I write about information assurance topics, including applications of confidentiality, control, integrity, authenticity, availability and utility across the entire spectrum of human activity. True, this column covers tightly construed system- and network-security topics, but it also occasionally delves into national security, public policy, human resources management, operations management and cyberlaw. I often write columns aimed at employee (and public) education from a security-awareness perspective because I hope that readers will freely use the columns in their organizations’ awareness newsletters. I have often explicitly urged security professionals to become involved in public-policy issues where our expertise can be useful to fellow citizens, and I hope that most readers find these commentaries at least interesting and at best stimulating, even if they disagree with some of my analyses and suggestions.

I include expressions of personal values in my writing for two reasons. First, I’ve always emphasized the value of a direct connection between writer and reader (see my essay “On Writing” in HTML or PDF). Writing in the first person rather than a disembodied, neutral and neutered third person and using the active voice rather than the passive are important elements in reaching readers; so is the direct expression of feeling and values.

Second, in all of my university teaching for the last 36 years, I have emphasized the importance of values regardless of the specific subject at hand. That doesn’t mean that every lesson or every column (yes, columns are an opportunity to teach) is an opportunity for self-indulgent self-expression; however, a subject-appropriate comment is useful in sparking interest and focusing the reader’s attention – regardless of whether the reader likes the comment or not.

For example, when teaching statistics, I include comments about the importance of meticulous attention to detail and emphasize double-checking methods and results; in systems engineering or technical support, I urge students to be respectful of users and to resist demeaning language; when teaching management topics, I introduce questions of human values such as respect for human beings (as opposed to treating workers as fungible automatons) because, I argue, they are underlying moral values that support good management (see for example these lectures). Similarly, in teaching security management, I include discussions of ethical decision-making as important tools for anyone setting and applying security policies (see for example the curriculum here).

Finally, I’d like to address the readers who have told me what _not_ to write. I’m always delighted to receive constructive suggestions about new topics; indeed, sometimes I’ve received such thoughtful commentaries that I have helped the writers publish their work in this column or elsewhere. However, I have never written to columnists to tell them _not_ to write something because I dislike it or am not interested in it! I don’t understand the basis on which a reader of a columnist’s work could write such a letter – especially when it is directed solely at the editor and not to the writer – even were the reader to be _paying_ for the column. If you disagree with something I write, by all means write to me to explain why you disagree – and maybe I’ll publish your comments (with your permission).

But don’t tell me what NOT to write in my column!