Re: [fw-wiz] i-cap proposals

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 02/22/05

  • Next message: ArkanoiD: "Re: [fw-wiz] i-cap proposals"
    To: ArkanoiD <ark@eltex.net>
    Date: Tue, 22 Feb 2005 11:25:24 -0500 (EST)
    
    

    On Tue, 22 Feb 2005, ArkanoiD wrote:

    > That depends on network AUP much. Don't know for US but here in Russia the
    > most common privacy policy is not to interfere with employees personal
    > communications unless there is a pretty explicit reason for investigation.

    Since I generally do incident response, forensics and the like, I tend to
    see more "explicit reasons" than most.

    > It is considered unethical. Company's security service should be legally
    > allowed to, but not on the will.

    I prefer to keep things separate so that such issues don't happen. I've
    seen way too much "personal" stuff on company machines that shouldn't have
    been there. I've also had to deal with the "co-worker walked past when
    the offensive e-mail popped up" stuff too.

    > >
    > > However, I will categorically state that the places I've been where folks
    > > don't allow personal access and where they do monitor for compliance have
    > > significantly less "recreational" activity going on during business hours.
    > > But then those places don't have issues with non-compliance because they
    > > don't change the policy if it isn't popular, they change the employee if
    > > they can't comply.
    >
    > Things are not always that simple. Speaking for me, working in environment where
    > i am not allowed to do recreational things on my workplace and communicate to outside
    > should at least double my income to be acceptable.

    I always negotiate this explicitly, but that's then part of the policy-
    not an exception to it. I've had the chance to make lots more money
    working in much more restrictive environments, and decided to decline- but
    that doesn't mean those environments should change their policies to be
    more liberal to attract me.

    > Compartment mode systems are sometimes cheaper ;-)

    Sometimes, but that's up to the policy. The thing is that it's not
    necessarily inherently bad to limit such access, and it's probably always
    bad to change a policy because of popularity rather than risk, business or
    other driving reasons.

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: ArkanoiD: "Re: [fw-wiz] i-cap proposals"

    Relevant Pages

    • Code This: Lousy bigot (Was: Re: Superman Rerun out of theatres ...)
      ... This is Verizon's policy on the acceptable use of the Service. ... Verizon reserves the right to deny Service to you, ... or of a sexually explicit or graphic nature; ... information on newsgroups which is not in the topic area or charter ...
      (rec.arts.comics.dc.universe)
    • Re: [PATCH] Smack: Simplified Mandatory Access Control Kernel
      ... The MLS systems from the 1990's could do all that without the complexity required by SELinux policy. ... SELinux integrates privilege into the policy mechanism. ... Here's an argument for why implicit labeling is good and explicit labeling is bad: If your process wants to label things explicitly it needs special privileges to do so, and it can abuse those privileges. ...
      (Linux-Kernel)
    • Re: iptables disables outbound traffic
      ... > explicetly close those ports too. ... > A not too uncommon policy is; ... > explicit drop secured high number ports ... $IPT -P OUTPUT DROP # Set default policy to DROP ...
      (comp.os.linux.misc)
    • Re: Archive in NY Times
      ... Bzl. ... > But there was also some question as to how explicit the band's permission ... Mr. Barlow said the band had had a policy since 1997 that "we had no ... > more problem with someone digital file sharing than we had with tape ...
      (rec.music.gdead)
    • Re: Intermittant GPO failure to apply
      ... Nick ... > Windows cannot query for the list of Group Policy objects. ... > Network Client digitally sign communications: ... >> For the attachments, it should be the problem of our newsgroup server, I ...
      (microsoft.public.windows.server.sbs)