Is it normal for sysadmins to own tickets on vulnerability reports?
Posted by _TR-8R@reddit | sysadmin | View on Reddit | 116 comments
Currently in my first full sysadmin role (done some junior admin work + analyst/engineering roles) and also my first time working for an MSP. I'm the only onsite tech for a client of roughly 60 users. We have a couple different vendors running internal vulnerability scans, and my boss tells me its my responsibility to get those reports every month, summarize writeups on and then create/own tickets internally for resolving those issues.
I'm not sure if this is normal but this feels like a lot of work and also like I'm owning/driving security issues, which I'm not specialized in and don't even have certs for. On top of that we have an internal security team and the client pays for a flat number of hours per week from a dedicated security engineer. I feel like this shouldn't be my responsibility but I don't know if that's normal or not and I don't want to come across like I'm being lazy, but at the same time any other role I've had once something is a security issue it gets handed off to them. I feel like all the reports should go to that team and if they need me to do remediation they'll let me know.
116 Comments
brispower@reddit
InlineUser@reddit
Bogus1989@reddit
rosseloh@reddit
Bogus1989@reddit
Yupsec@reddit
Bogus1989@reddit
Yupsec@reddit
Bogus1989@reddit
Bogus1989@reddit
SideScroller@reddit
networkn@reddit
SideScroller@reddit
dustojnikhummer@reddit
SideScroller@reddit
networkn@reddit
SideScroller@reddit
networkn@reddit
SideScroller@reddit
Old_Acanthaceae5198@reddit
fakename4141@reddit
spittlbm@reddit
ec1548270af09e005244@reddit
hurkwurk@reddit
architectofinsanity@reddit
fio247@reddit
architectofinsanity@reddit
BoomSchtik@reddit
hou6_91@reddit
thecrabmonster@reddit
tf_fan_1986@reddit
TubbaButta@reddit
cowprince@reddit
brispower@reddit
Wickedhoopla@reddit
Downinahole94@reddit
chemcast9801@reddit
Artistic-Still-837@reddit
Rhythm_Killer@reddit
px13@reddit
Zenkin@reddit
Cheomesh@reddit
bonebrah@reddit
maziarczykk@reddit
inaddrarpa@reddit
Cheomesh@reddit
TurboHisoa@reddit
fdeyso@reddit
Fatality@reddit
Fatality@reddit
bbqwatermelon@reddit
_TR-8R@reddit (OP)
Steve_78_OH@reddit
illicITparameters@reddit
Steve_78_OH@reddit
illicITparameters@reddit
Steve_78_OH@reddit
illicITparameters@reddit
Steve_78_OH@reddit
inshead@reddit
illicITparameters@reddit
d3rpderp@reddit
_TR-8R@reddit (OP)
d3rpderp@reddit
phoenix823@reddit
iheartrms@reddit
_TR-8R@reddit (OP)
Hotshot55@reddit
BiscottiNo6948@reddit
IMplodeMeGrr@reddit
BiscottiNo6948@reddit
IMplodeMeGrr@reddit
maziarczykk@reddit
Royal_Bird_6328@reddit
serverhorror@reddit
byteme4188@reddit
_TR-8R@reddit (OP)
dio1994@reddit
byteme4188@reddit
dio1994@reddit
chalbersma@reddit
_TR-8R@reddit (OP)
chalbersma@reddit
halodude423@reddit
siscorskiy@reddit
Character_Deal9259@reddit
midwest_pyroman@reddit
Bogus1989@reddit
Bogus1989@reddit
Bogus1989@reddit
aXeSwY@reddit
Djblinx89@reddit
BoomSchtik@reddit
Cutoffjeanshortz37@reddit
owlwise13@reddit
pegz@reddit
number4drunkenuncle@reddit
Consistent-Baby5904@reddit
mrcluelessness@reddit
androsob@reddit
inshead@reddit
Rolli_boi@reddit
michaelpaoli@reddit
Vortech03Marauder@reddit
rootkode@reddit
GoodLyfe42@reddit
_Cold_Ass_Honkey_@reddit
LeTrolleur@reddit
LenR75@reddit
JankyJawn@reddit
fireandbass@reddit
syberghost@reddit
SirLoremIpsum@reddit
ISU_Sycamores@reddit
ZeroT3K@reddit
FerryCliment@reddit