You Shall Have No Other Gods Before Me

Recently I’ve felt compelled to write about the Ten Commandments. I’m not sure exactly why. I have been focused on the second and fifth especially recently, but I think part of the reason is simply to put forth my current view and interpretation before I begin my MA in Biblical Studies program in early 2027.

With that short preamble, let’s dive into the first.

You shall have no other gods before Me.

When Moses received the Ten Commandments from God, the Israelites had just been delivered from slavery in Egypt and were being formed into a covenant nation. They were also surrounded by cultures that worshiped many gods and often attributed natural events, military victories, prosperity, calamity, and other aspects of life to the actions or desires of those gods.

The God of Abraham, the One True God, the I AM, made clear that this was not acceptable. He was not simply to be first among many gods. He alone was to be worshiped.

Throughout the Bible, God shows Himself as a loving yet just God. Many seem to focus heavily on the loving part while diminishing, if not outwardly ignoring, the just attribute. Scripture also describes God as jealous, though I don’t think that word carries quite the same connotation as jealousy among humans. God’s jealousy is not rooted in insecurity or envy. Rather, He requires the worship, loyalty, and devotion that rightfully belong to Him alone.

To me, that is the heart of the First Commandment: seek God, worship God, and place no other god alongside Him. And those competing gods need not necessarily have names or statues.

In today’s world, I think this also means that the idea that all religions ultimately lead to the same God is incompatible with the First Commandment from a Christian perspective.

The First Commandment seems to leave little room for the idea that God is simply one valid option among many. If He is truly the One True God, then He alone is worthy of worship.

That is my primary takeaway from the First Commandment.

What’s yours? I welcome comments below.

Image by Grok

Agitated

I’m a bit agitated.

The agitator in my washing machine has been having issues agitating. I, sensing a rare opportunity to perhaps use a bit of learning from my undergraduate degree decades ago (BS Mechanical Engineering, University at Buffalo, 1993) jumped at the chance to diagnose and possibly fix. I correctly deduced the root cause (worn splines) and a “temporary” fix: thorough cleaning, new bolt to hold agitator down on splines, with locking fluid on bolt.

This worked for a while, but we knew it was only a temporary solution; at some point in time the gearbox would need to be replaced. I decided that while I could do it myself, I wouldn’t want to (one of Schaffer’s Rules: Just because you can do something doesn’t mean you should). Thus, I called in a pro with a catchy name and smart uniform that had great reviews and just oozed “professional.”

What does this have to do with cyber security and information security, you may ask? I’m getting to that.

The technician provided the expected diagnosis but could not provide an estimate without internet access. I know this because he asked me for my WiFi password to connect.

That agitated me.

My answer was, of course, no, and also that I did not have a Guest network. Honestly, even if I did, I would be reluctant to share. You come to my place for service, you bring all your own tools. You’d never think to ask for a wrench, correct? Why ask for WiFi?

His reaction conveyed entitlement; how could I refuse such a simple request?

I sensed a teachable moment. “Why not use your phone’s hot spot?”

“How do I do that?”

Minutes later I had estimate in hand after providing my free consulting, to which he thanked me (yet refused my suggestion of barter for free washing machine service). He had another tool in his arsenal, no longer having to ask service callers for confidential infrastructure information. How many home networks did I help secure today?

Not that any of that mattered in the moment. The cost to fix the washer would be about what a new washer would cost, and thus us the path we will follow. I’m sure someone will get that old washer and remove usable parts and recycle the rest or perhaps fix it and sell or use.

Controls Are Means, Not Ends

I ran a half marathon Sunday. I finished first in my age group. This despite a decidedly unconventional training routine.

For much of my adult life, I’ve been a fairly consistent amateur runner. I’ve never been exceptionally fast, but PRs from years past include a sub-22-minute 5K, a half marathon below 1:40, and a couple of marathons below four hours. I believe my marathon PR was 3:47 at Las Vegas in 2010, but I’m going on memory.

Over the years, I’ve learned how to train. I’ve done the 10-week mileage programs. I’ve logged hundreds of miles preparing for a single event. That’s the proven method. That’s the way you’re supposed to do it.

We say that a lot in information security, don’t we?

For this half marathon, I logged a total of about 17 miles of training runs over 10 or so weeks. Not 17 miles per week. Seventeen miles total. That includes a July 4th 5K event, a couple of fun trail runs, and a seven-mile “wake up” trail run about a week before the race.

Yet I didn’t just survive the half marathon and finish. I won my age group with a respectable time, at least for this 59-year-old male, of 2:18.

How?

I do a lot of cycling, both indoors on Zwift and outdoors mountain biking. My resting heart rate is in the 40s, and my VO2 max remains strong for my age. Those activities have built and maintained an aerobic system capable of handling much more than cycling. Years of running experience, some limited running-specific conditioning, and knowing how to pace myself took care of other parts of the equation.

In other words, I didn’t follow the conventional control. But I still addressed the underlying risks.

Back to information security.

I occasionally see discussions about “compensating controls” in a disparaging sense. One LinkedIn thread I saw recently slammed the very idea of compensating controls, arguing that we shouldn’t need them if the primary control is designed properly.

I think that misses the point.

We should not put the controls first. We should concern ourselves first with the risks we’re trying to mitigate.

Too often, “compensating control” becomes a compliance term rather than a risk-management concept. We start with a prescribed control, discover that we can’t or don’t want to implement it exactly as prescribed, and then ask what “compensating control” we can put in its place.

But why are we starting with the control? Start with the risk.

Back to running. What were my risks? I might have a crappy time. I might not finish. I could hurt myself. I could really hurt myself.

None of those risks inherently says that I must follow a conventional running mileage program to mitigate them. Through experience and conditioning, I’ve found another way to address much of the risk. In fact, I would argue that my approach may be better for me because it reduces the pounding on my knees while maintaining a strong aerobic base.

That doesn’t mean cycling magically replaces every benefit of running. It doesn’t. Just as in information security, one control doesn’t necessarily address every dimension of a risk. My aerobic conditioning addressed one component. Running experience, limited running-specific training, pacing, and knowing my own capabilities addressed others.

The objective wasn’t to comply with a running standard.

The objective was to manage the risks well enough to achieve the desired outcome.

Seventeen miles of running wasn’t the standard way to prepare for a half marathon. But the standard wasn’t my objective. Managing the risks was.

So perhaps we should stop spending so much time debating “primary” versus “compensating” controls. Better yet, stop making controls the starting point for information security. Identify the risks. Understand the outcomes you’re trying to prevent. Then identify the combination of controls that mitigates those risks effectively and provides the resilience the organization needs.

Controls are means, not ends.

That’s how we build high performance, whether we’re talking about running a half marathon or building an information security program.

Photo: The author crossing the finish line at the 2026 Fall Creek Falls Half Marathon. Todd Temple Photography