Comment Re:More of a System Administration Challenge (SAC! (Score 1) 66
I led a team that competed in one of the qualifiers and found the competition extremely wanting. It's more of an arcane system administration challenge rather than anything about security. Some responses to the competition are collected at my lab's blog here:
http://isisblogs.poly.edu/2008/02/29/pre-neccdc/ (see the comments)
I agree with you completely. I was a captain for a team that made it to the finals the first year they held nationals. The majority of business injects are related to system administration. Most of the strategies to win involve patching quickly and changing stupid defaults (among other things). However, I don't complain too much because it is a fun experience. Also, I haven't come up with better "rules" for the game. One of the biggest challenges was to devise a security competition that didn't promote hacking. That makes bad press and also makes it very difficult to obtain corporate sponsorship.