Great Circle Associates Firewalls
(September 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Software concerns
From: pnh1rgr @ mclo10 . med . navy . mil (Bob Resino)
Date: Fri, 08 Sep 1995 14:07:10 -0400
To: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security), firewalls @ greatcircle . com

[Snip]
>3) Product has been reviewed (as in 1) by someone trusted.
>
>(1) is obviously the most rigorous but also the most time consuming.
>(2) is more involved & generally requires being personally acquainted
>    with the principals. Biggest problem is proving that they are free 
>    from outside interests/pressures.
>(3) being in the USA I would trust a review by the NSA and a very few others.

Don't know if I could trust them Padgett.  DISA took NSA at there word about C2 
WIN NT(AS) 3.5 and didn't look real close at the platform it was submitted on.
DISA has now approved the installation of NT boxes on DISN.  For more info, see 
the 4 Sept issue of Government Computer News.

>
>Buying security is different from buying a wordprocessor and must be weighed
>against what is at risk and the effect on your customer base if an
>exception occurs. Obviously this is going to have different values for
>an .EDU as opposed to a DoD contractor (well maybe if the .EDU relies
>on grants...).
>
>Many remember WYSIWYG - my motto is WYDSIWGY "What you don't see is what
>gets you".
>
>					Warmly,
>						Padgett
>
>ps 10,000,000 lemmings can't be rong.

pps:  ...nothing up my sleeve.  Hey Rockie, watch me pull a rabbit out of my
hat...
                                                        B. Moose

---------------------------------------------------------------
Bob Resino (RGR24) pnh1rgr @
 pnh10 .
 med .
 navy .
 mil (804)398-7400
Healthcare Support Office                 Fax:(804)398-7265
Medical Construction Liaison Department   
Management Information / Data-telecommunciations Div (Code 55)
6500 Hampton Blvd               "To be or not to be...
Norfolk, VA  23707              What was the question ?"  
---------------------------------------------------------------
The opinions are mine, NOT those of the Navy or the Healthcare
Support Office.  If they happen to be the same, its got to be
coincidence!


Indexed By Date Previous: Re: linux vs. *bsd for secure networking system
From: sdw @ lig . net (Stephen D. Williams)
Next: Re: upgrade to commercial firewalls
From: "Hung Vu" <hungv @ mail . fonorola . net>
Indexed By Thread Previous: Software concerns
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Next: Interpreting CERT advisories
From: Brent @ GreatCircle . COM (Brent Chapman)

Google
 
Search Internet Search www.greatcircle.com