Re: [fw-wiz] Citrix vs OWA

From: Victor Williams (vbwilliams_at_neb.rr.com)
Date: 06/18/05

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Re: InfoSec's Waterloo and it's implications"
    To: "Paul D. Robertson" <paul@compuwar.net>
    Date: Sat, 18 Jun 2005 10:32:50 -0500
    
    

    > Do the assessment, or have someone do it for you- then provide them with
    > the "if we do this, there's a risk of that" stuff in writing- then they
    > get to choose if they want to take the same risk as "everybody else."
    >
    > FWIW, I'd do one-time tokens for OWA *or* Citrix just to make sure that
    > the user's responsibility is upheld.
    >

    I second that. I'd do everything Paul said...bring in a 3rd party to
    the risk assessment who is seemingly neutral.

    The one-time token thing has also gotten a LOT less expensive in
    up-front dollars to implement. BUT, do the risk assessment FIRST.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "Re: [fw-wiz] Re: InfoSec's Waterloo and it's implications"

    Relevant Pages