3 ms·
Just pointing out that none of the security issues written about in the article appeared to be related to it being an external service. Their problems seemed t
by tedsuo 11y ago
Just pointing out that none of the security issues written about in the article appeared to be related to it being an external service. Their problems seemed to be:
a) no one actively admining the service, in particular removing accounts when people left.
b) users themselves were communicating things they were not supposed to, like instructions for circumventing other security procedures.
You can just as easily have these problems with an internal service.
Telling is that the illegal advice VA staff were giving each other had to do with circumventing other security procedures that were interfering with their ability to work effectively (like needing to be available via email but not having access to email on an available device). These are issues all big organizations face, regardless of whether they are purchasing IT services or implementing themselves.
- solipsism 11y agoYou can just as easily have these problems with an internal service. Not for the typical definition of "internal". Typically to reach an internal service you have to be on the internal network. Removal of an ex-user's intranet credentials is usually something IT handles well.