Firewall Wizards mailing list archives

Re: Security Policy methodologies


From: Rick Smith <smith () securecomputing com>
Date: Wed, 7 Jan 1998 08:24:24 -0600

At 8:09 AM -0800 1/6/98, Larry J. Hughes Jr. wrote:

I don't think that the 'what is my statistical liklihood of being
attacked?' question is necessarily the right one to be asking.

Given the intrusive nature of security solutions, I believe this is
*exactly* the question to be asking. You want the maximum amount of
deterrence with the minimum amount of cost and inconvenience. You'll accept
more inconvenience only if the threat warrants it.

First, what is your statistical liklihood of your office being burgled?
....  In the
end do you really care or do you want to install an alarm and a few locks?

Statistical likelihood (or more likely, an intuitive estimate of the
likelihood) is an essential part of the decision process. Are locks enough?
Do you need an on-site guard as well? Do you need bars on the windows? Do
you need a safe, and if so, what belongs inside. What type of alarm do you
need: silent, noisy, call-the-station, etc. The decisions are based on how
attractive a target you are as well as where you are located. Each site
makes its own choices based on management's assessment of risk and/or the
standards for that industry.

When I give talks on crypto applications I always portray crypto as a
deterrence game designed to discourage attackers. I usually manage to upset
one or two audience members because I identify flaws, major or minor, in
just about everything. There's always a weakness in a real, working system,
but folks will always yearn for certainty.


Rick.
smith () securecomputing com                Secure Computing Corporation
"Internet Cryptography" at http://www.visi.com/crypto/ and bookstores




Current thread: