We call them "CISSPs" where I have worked. It's a mostly derogatory term for whiteboard warriors of the security world. They usually have a CISSP but no other valuable security background, most certainly aren't programmers and have never even played with Metasploit let alone understood how you exploit a system.
Unfortunately (most) banks/big enterprise are full of CISSPs which is why they keep getting styled on all the time.
If they woke up and hired real hackers, adopted real security practices and knowledge sharing they could drastically reduce risk and probably get better software and systems in the process.
Unfortunately (most) banks/big enterprise are full of CISSPs which is why they keep getting styled on all the time. If they woke up and hired real hackers, adopted real security practices and knowledge sharing they could drastically reduce risk and probably get better software and systems in the process.