Firewall Wizards mailing list archives
Re: Security Policy methodologies
From: Rick Smith <smith () securecomputing com>
Date: Wed, 7 Jan 1998 08:24:24 -0600
At 8:09 AM -0800 1/6/98, Larry J. Hughes Jr. wrote:
I don't think that the 'what is my statistical liklihood of being attacked?' question is necessarily the right one to be asking.
Given the intrusive nature of security solutions, I believe this is *exactly* the question to be asking. You want the maximum amount of deterrence with the minimum amount of cost and inconvenience. You'll accept more inconvenience only if the threat warrants it.
First, what is your statistical liklihood of your office being burgled? .... In the end do you really care or do you want to install an alarm and a few locks?
Statistical likelihood (or more likely, an intuitive estimate of the likelihood) is an essential part of the decision process. Are locks enough? Do you need an on-site guard as well? Do you need bars on the windows? Do you need a safe, and if so, what belongs inside. What type of alarm do you need: silent, noisy, call-the-station, etc. The decisions are based on how attractive a target you are as well as where you are located. Each site makes its own choices based on management's assessment of risk and/or the standards for that industry. When I give talks on crypto applications I always portray crypto as a deterrence game designed to discourage attackers. I usually manage to upset one or two audience members because I identify flaws, major or minor, in just about everything. There's always a weakness in a real, working system, but folks will always yearn for certainty. Rick. smith () securecomputing com Secure Computing Corporation "Internet Cryptography" at http://www.visi.com/crypto/ and bookstores
Current thread:
- Re: Security Policy methodologies Rick Smith (Jan 01)
- Re: Security Policy methodologies Ted Doty (Jan 02)
- Re: Security Policy methodologies Aleph One (Jan 03)
- Re: Security Policy methodologies Marcus J. Ranum (Jan 03)
- Re: Security Policy methodologies Ted Doty (Jan 05)
- Re: Security Policy methodologies Aleph One (Jan 05)
- Re: Security Policy methodologies Ted Doty (Jan 05)
- Re: Security Policy methodologies Larry J. Hughes Jr. (Jan 06)
- Re: Security Policy methodologies Rick Smith (Jan 07)
- Re: Security Policy methodologies Ted Doty (Jan 07)
- Re: Security Policy methodologies Aleph One (Jan 03)
- Re: Security Policy methodologies Ted Doty (Jan 02)
- <Possible follow-ups>
- RE: Security Policy methodologies Rick Smith (Jan 01)
- Re: Security Policy methodologies Aleph One (Jan 03)
- Survey so far - Security Policy methodologies Bret Watson (Jan 04)
- Re: Security Policy methodologies Anton J Aylward (Jan 06)
