Educause Security Discussion mailing list archives

Re: Thoughts on Jericho Forum


From: Gary Flynn <flynngn () JMU EDU>
Date: Tue, 19 Jun 2007 12:24:05 -0400

David Morton wrote:

Have the principals of the Jericho Forum been discussed at your
organizations and if so, what has come out of those thoughts and
discussions?

I look forward to results from their efforts. Universal access
to integrated applications indeed necessitates better security
controls closer to the items being protected.

However, when "unbreakable" databases, "secure operating systems",
and a wide variety of "security applications" have frequent design
and programming mistakes negating their security controls, which
are sometimes exploited before a solution is available to fix them,
I'm not ready to put my trust totally in the end-points. Even in
the absence of product defects, inevitable human mistakes by
implementors and operators necessitate a defense in depth strategy.

Perhaps when some of their commandments are more thoroughly
implemented in the installed base of software, protocols, networks,
machines, and people. :)

- All devices must be capable of maintaining their security policy
  on an untrusted network

- All people, processes, technology must have declared and
  transparent levels of trust for any transaction to take place

- Mutual trust assurance levels must be determinable


--
Gary Flynn
Security Engineer
James Madison University
www.jmu.edu/computing/security

Current thread: