Re: Defending yourself against Nazi IT departments



Bogwitch <Bogwitch@xxxxxxxxxxxxxxxxxxx> wrote:
Dana wrote:
"Bogwitch" <Bogwitch@xxxxxxxxxxxxxxxxxxx> wrote:
It is a tricky one, an IT department may have technical skills in
excess of a security team but that is down to the HR department to
ensure relevant personnel are selected.

The separation of duties principle comes into play here.

True, the separation is needed. What is more important is staffing
your IT department with people who are more than just plain windows
techs. Most window techs/admins no very little about
networking/security/telecommunications in general

I have to disagree with you there. Yes, it would be useful to have
experienced, knowledgeable IT staff but more importantly, they should
be trustworthy.

Wrong. They MUST be both knowledgeable AND trustworthy. If they're
knowledgeable but not trustworthy your security may be breached on the
social level. If they're trustworthy but not knowledgeable your security
may be breached on the technical level. Either way you lose.

And could you guys *please* learn to trim your quoting?

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich
.



Relevant Pages

  • Re: Defending yourself against Nazi IT departments
    ... knowledgeable but not trustworthy your security may be breached on the ... social level. ... If they're trustworthy but not knowledgeable your security ... I thought it was a given that the staff would have sufficient knowledge to perform their assigned tasks, else they should not have been given the job. ...
    (comp.security.firewalls)
  • Re: COM+ / NET Components
    ... I need to create some .Net components to run in COM+ and works with ... mostly because of security (the client demand that the ... You don't have to go through this for true separation of tiers. ... If you look at Juval Lowy's work, the idea of setting up a WCF service over ...
    (microsoft.public.dotnet.general)
  • Re: ACL
    ... All security policy that is site specific must be in writing. ... If the standards are not in writing, ... there's no legal reason for the sysadmins to access the particular data, ... SELinux in no way reduces the need to hire trustworthy people. ...
    (RedHat)
  • Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?
    ... >> of measurable security benefit. ... > manage a network which was formed years before UPnP was invented. ... is trustworthy and what makes it one way or another. ... I could try and preempt the entire discussion by saying unless you've ...
    (Firewall-Wizards)
  • Re: [PATCH] signed binaries support [0/4]
    ... Our main focus was to implement a way to inhibit execution ... of suid-binaries, which are not trustworthy. ... setuid binaries hardly brings a real security gain. ...
    (Linux-Kernel)