2 ms·
I think the bigger problem is that business people and managers expect security to just work the way they intend without them having to even think about what th
by waps 12y ago
I think the bigger problem is that business people and managers expect security to just work the way they intend without them having to even think about what the correct security policy for X is. When you don't want to think about it and do want to share stuff the only tolerable security policy is public access, at least within the organisation.
Then they proceed to give a domain account to the janitor ... and then the customer list leaks.
Like most other problems at banks, the issue here is large amounts of stupid people, especially at the top.
- dragonwriter 12y ago> I think the bigger problem is that business people and managers expect security to just work the way they intend without them having to even think about what the correct security policy for X is. When you don't want to think about it and do want to share stuff the only tolerable security policy is public access, at least within the organisation. I think the bigger problem in enterprises is UX failure -- not necessarily of computer systems, but of the human systems by which access is managed. Its not that managers don't want to think about security, its just that IT security organizations often don't present a clear, consistent, efficient (in time and effort) interface to their customers to implement security policy, and management works around that by demanding broader access (in the limit case, public access) than is necessary, because otherwise the basic work can't get done. Security organizations very often forget that usability -- both of the secured systems and of the process by which the business owners of systems manage access -- is as important to effective security as technical safeguards.