About Operating Systems security

From: yannick'san (yannicksan_at_free.fr)
Date: 05/27/03

  • Next message: steve baker: "Distressing, possibly life threatening emails from free accounts (yahoo, hotmail"
    To: <security-basics@securityfocus.com>
    Date: Tue, 27 May 2003 20:55:02 +0200
    
    

    Hello everybody,

    First of all, I know the subject I'm going to talk about has largely been
    discussed everywhere but, up today, the main problem I have is that I can't
    really find the right Documentation I'm looking for and as much as I read
    reports, the task become harder to do. So, now, I ask for some helps to the
    list...
    Ok, here I start. Considering the following fonctionnalities installed and
    the same machine and nothing more :
    (a) a firewall
    (b) a web server
    (c) a database
    I have already prouved that the security level will be the highest if I use
    OpenSources for (a,b,c), and for reaching that point, not only the security
    process and procedures has already been written (Process and procedures for
    regularly auditing the fonctionnalities installed and also for dealing with
    a recovery plan, for exemple) but also the code and reviews that could be
    done or have been done.
    But as (a,b,c) is supported by an OS, the hardest problem I have is how to
    introduce a new one in a companie - Probably I should have started to think
    about that before...- How to prove that the OS choosen for only supporting
    the fonctionalities ennonced before, will be the most secured OS between
    all. How to prove that it in front of directors, managers and Engineers.

    Any pointers, news or documents are welcome and I'll keep everybody informed
    on the result :)

    -Yannick

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: steve baker: "Distressing, possibly life threatening emails from free accounts (yahoo, hotmail"

    Relevant Pages

    • Re: Naming the stick
      ... >>> I would appreciate seeing some documentation or other ... >>> supporting evidence that 100klb upper stages were ... So the CCB must be capable of taking a load of over 70 ...
      (sci.space.policy)
    • Re: Naming the stick
      ... >> I would appreciate seeing some documentation or other ... >> supporting evidence that 100klb upper stages were ... The design for the A-V CCB originally intended to carry a standard ...
      (sci.space.policy)
    • Re: Genealogical records
      ... I use Family Tree maker to collect my genealogical information and ... documentation supporting the data for the death. ... How do others working in genealogy organize all of this supporting ...
      (soc.genealogy.methods)
    • Re: problems with RANU2?
      ... Your best bet would be to use a RNG that has supporting ... Also the Fortran 77 code for RAND: ...
      (comp.lang.fortran)
    • Re: Problems with simple Samba file share
      ... > How do I know what my security level is? ... Isn't there a GUI interface ... > to this security service/system? ... Is there any documentation? ...
      (comp.os.linux.misc)