3 ms·
IA person here. Good IA people know how to evaluate risk. Bad IA people show up for the salary and point to a policy which says 'no' (i.e., not actually evalu
by equalunique 10y ago
IA person here.
Good IA people know how to evaluate risk.
Bad IA people show up for the salary and point to a policy which says 'no' (i.e., not actually evaluating risk)
Ad-hoc proper IA requires evaluating your project according to a checklist of security controls. It could very well be something about open source doesn't fit well with those controls. The answer is to change the policy, then change the controls, and finally, pass your compliance checks.
Idk about DoD, but US Dept of Veterans Affairs is doing better with open source. Their bread&butter application, VistA, is open sourced. Their Technical Reference Model (TRM) is a catalog of approved/unapproved software. NodeJS and a lot of NPM packages are approved.