Showing posts with label kristine sihto. Show all posts
Showing posts with label kristine sihto. Show all posts

Monday, 2 July 2018

Highlights - June 2018 - AWSN blog


Okay where has January gone?  In case you missed any of the posts for June 2018 the following were published:


Guest Post - IoT - Brigitte Lewis



(c) AWSN 2018

Disclaimer: The views and opinions expressed in this article are those of the author/s and do not necessarily reflect the official policy or position of any agency, organisation or association.

Sunday, 3 June 2018

Guest Post - Write to be Read - by Kristine Sihto


This is a guest post by one of our regular contributors, Kristine Sihto

We are writers, all of us, in this age. Every text, every tweet, every email creates a documentary trail of our existence. We are each an author of an autobiography that extends over multiple platforms and locations, in our personal and our professional lives, whether we intend that creation or not. Writing is ubiquitous in our lives.

But just because a thing is written, that doesn’t mean ‘written well’. 

Bad writing fails to communicate efficiently and can lead to misunderstandings, lost time, frustration, and can impact the way people view your professionalism and ability.

The key to good writing is clarity. 

This extends across the entirety of writing, from choosing the correct homophone or punctuation, through to writing for the intended audience; every writing ‘error’ comes down to a failure to communicate efficiently. The page strips out the contextual information you would normally see in face-to-face communication, such as pitch and tone, facial expression, and body language. For this reason, clarity in writing needs to be far more accurate and comprehensive than a conversation would be.

Clarity tips:

  • Write for your target audience. This is especially important if you’re conveying highly technical information.
◦          Even if you’re writing for an informed audience, assume that you know a lot more than they do, and explain your working.
◦          Where instructing or explaining a process, use ‘show and tell’ formats (such as screenshots or step-by-step photographs) if you can. These can be easier to follow than purely text-based instructions.
◦          If your audience isn’t technical, but your content is, remember that. Write in a way that avoids unnecessary details and explains concepts that may be unfamiliar. If you can write in such a way as to be understood by a teenager, you’ve hit the right balance.

  • Limit the number of words in a sentence. If you’ve got 50 words in your sentence and you don’t have any punctuation inside it, it will be hellish for the reader to try to comprehend. A long sentence can usually be broken up into two or more sentences with a little restructuring, and your readers will have a more pleasant experience.
  • It should never be assumed that the reader has the same level of knowledge as you, or that they have the same lexicon. If you need to use jargon, provide glossaries. If you need to use acronyms or initialisations, write them out fully the first time.
  • Use a spell checker program. However, you shouldn’t rely entirely on your spell checker, especially if you know you have bad spelling. Read each of the options the spell check offers you before accepting the default option, because computers are often wrong.
  • Use a text-to-speech screen-reader to play your writing back to you. Listening to your text can highlight words that have been used incorrectly, or grammatical issues like sentence fragments or run-on sentences.
  • Get another human to read your writing, preferably someone who is pedantic about small errors. You should, however, make sure it’s someone who is more invested in the outcome of your writing than they are in their relationship with you. Close friends and family members may wish to save your feelings, and may be overly optimistic about the quality of your work. It’s also important that you are gracious about accepting critique; bad responses to honest critique can destroy the credibility of future critique, as your proofreader may decide to lie in order to keep the peace.
  • In all instances, write as simply as you can, using plain English. This includes when writing to C-suite executives. Executive levels of management have to read all day, and they’re just as human as you or I am. Making a document easy to understand is key to getting the words read and understood. This isn’t Scrabble; there is no scoreboard, and big words don’t earn you more points.
Source of image unknown
These are not examples I have picked from the blue. Throughout the years I have been editing, the consistent issues I come across time and again are:

  1. Assuming the reader has the foundation knowledge to understand you (lack of glossaries, using unexplained acronyms or initialisations, writing for the wrong target audience).
  2. Not allowing enough opportunity for the reader to pause and comprehend meaning (run-on sentences, lack of punctuation).
  3. Using sentence fragments (either through forgetting to finish a thought, or through a misunderstanding of grammar).
  4. Over-reliance on spell checkers (incorrect/inappropriate wording) or lack of spell checking (spelling errors throughout a document).
  5. Trying to impress (executing overtly loquacious confabulation with an aspiration to appear astute and resourceful).

If you can avoid these five things, your writing can appear more polished and professional.

________________________________________________
If you are interested in writing a guest post for this blog please read the submission guidelines here >> AWSNblog-guest_post_guidelines <<

(c) AWSN 2018

Disclaimer: The views and opinions expressed in this article are those of the author/s and do not necessarily reflect the official policy or position of any agency, organisation or association.

Sunday, 18 March 2018

Infosec for Beginners: Cracking the Linguistic Fortress - by guest writer Kristine Sihto

This article first appeared in the second newsletter of the Brisbane AWSN Chapter. 

Kristine Sihto has been writing intermittently over the past three decades. Most recently, she has found joy in technical writing for Alcorn Security Group. Kristine has plans to self-publish a book of poetry in 2018


Information security can be a hard nut to crack. Infosec professionals come from a wide range of disciplines, with a wide range of backgrounds, but the stories I hear most often are of people coming into Information Security purposefully, scaffolding their pathway through closely related fields. There are people wanting to break in, but can’t find that pathway. They don’t know the right people, they don’t have the foundation skills.
I’m very new to information security. Less than eighteen months, in fact. My current role is technical writer for a security assurance firm, but I came from a background of editing and compliance within vocational training. I hadn’t really worked in depth with IT, and the compliance work I had done really only scraped the surface of data protection.
There is so much to learn in Information Security that people such as myself, who sidestep into the sector from somewhere unrelated, may find it quite impenetrable. The jargon is so pervasive that the people working with information security concepts on a daily basis may not realise that they are no longer using common English. This creates an enormous linguistic barrier to entry, especially when we start talking about ‘the cybers’.
Coming into the sector with a high level of literacy didn’t help with this barrier. Many terms mean different things outside of information technology or cyber security; terms like ‘credentials’, ‘authorisation’, ‘malicious user’, and (as a verb) ‘middling’ (which, as many cricketers will attest to, is the practice of hitting the ball with the middle of the cricket bat). Military terms like ‘attack surface’ may require a fair amount of logic and critical thinking to determine what they might pertain to, and some, such as ‘red team’, are so obscure as to require explanation.
The jargon is made even more impenetrable by the widespread use of acronyms and initialisations, which have no linguistic transparency and require prior knowledge to understand. Put a bunch of them together, and the poor idiot on the other end (e.g. me) has no idea what’s going on!
All is not lost however.
It’s possible to upskill in a reasonably short amount of time, given enough motivation to the task at hand. There are resources available that are easy to access, targeted at giving a baseline understanding of information security concepts, and most importantly, free.
Futurelearn has a brilliant series of cyber security MOOCs (Massive Open Online Courses) that I found to be especially helpful. Introduction to Cyber Security; Cyber Security: Safety at Home, Online, in Life; Cyber Security for Small and Medium Enterprises: Identifying Threats and Preventing Attacks. The entry bar for these courses is very low. The content is presented in a way that’s accessible to a range of learners, such as people with disabilities or people with lower literacy levels, and it covers all of the basics.
There are also free-to-access glossaries available online, and these may be useful not only for informing people new to Infosec, but also people who are being informed by information security, such as C-level executives. I found the Threatsaurus to be particularly useful. Glossaries such as this can assist in bringing newcomers up to the level of jargon usage that everyone else is using.
And of course, one of the best ways to feel your way into a field is to immerse yourself in it. Make connections through Twitter and LinkedIn; follow infosec blogs and podcasts (I listen to Security Weekly); engage with industry events and meetups, such as through AISA or AWSN. Listen and read on a regular basis, and there suddenly comes a point where you start to understand the words and concepts.
I believe it took me a solid six months to get to the point where I was familiar enough with terminology to feel comfortable that I wasn’t going to confuse everyone around me. I still am not at the point where I can take Google out of the equation, but in a highly technical role such as mine, I expect that my relationship with search engines will be a long-lasting one.

(c) AWSN 2018

Disclaimer: The views and opinions expressed in this article are those of the author/s and do not necessarily reflect the official policy or position of any agency, organisation or association.

Monday, 30 October 2017

On Writing

By Kristine Sihto


“Once upon a time, there was a girl. That girl dreamed of being a writer…”

I have always liked words. As a child, I had a stammer. Not enough for my parents to ever worry, but enough for me to hear my own voice and feel constantly ashamed. It was different when I wrote. On paper, there was no hesitation. No repeated consonants at the beginning of a word, no grasping for words that would never come to my lips – I could be eloquent and graceful and smart on the page.

When I was introduced to poetry in high school, I flourished. Adding deliberate structure into those words was like a dance. I could craft my words to mimic the ebbs and flows of water or the crackling flames of fire, use sibilance to sigh the wind’s whispers or rhythm to push the beat of a heart. I knew that I wanted to write. There was never an inkling that I would become a technical writer, however. Facts, I thought, were dull and dry; I wanted to be Tolkien or Blyton. I wanted to be Blake or Wright or Cummings. I wanted to fill the world with rhythm and language that would turn the head and speak to the heart.

It turns out that writing is hard without motivation. It takes effort and commitment to get up and write thousands of words a day with no solid incentive.
The drive that I maintained as a teen to write every day was slowly eroded by rejection letters and competing priorities, like dishwashing and children and television. The works-in-progress piled up as new ideas were born before the old ones had reached completion, and suddenly I was in my 40s and still dreaming that someday I would be a writer.
My break back into writing was a series of lucky events. A chance conversation put me into a professional editing role, and a few years later, another chance conversation found me in a technical writer’s position, in an industry I’d never considered before. That industry is Information Security.
Older eyes see that while there is a hazy, elusive value in the work that I dreamed of in my younger days, being able to explain facts on paper has solid worth. We communicate in written words: in policy, in reports, in emails, over the Internet. Clarity is essential.
I used to say that I could write anything I could understand. My role as a technical writer has forced me to revisit that idea. I research as I write, and often, as I am writing about something, I am learning it for the first time. It is poetry again, fitting concepts that are new to me into the structure of sentences, identifying the nouns and verbs and adjectives and making them flow in meaningful ways. I now see that I can understand anything that I can write. I no longer need to feel I can speak to the heart, so long as the head hears me.
 


About the author - Kristine Sihto has been writing intermittently over the past three decades. Most recently, she has found joy in technical writing for Alcorn Security Group. Kristine has plans to self-publish a book of poetry in 2018


(c) AWSN 2017

Disclaimer: The views and opinions expressed in this article are those of the author/s and do not necessarily reflect the official policy or position of any agency, organisation or association.