Great Circle Associates Firewalls
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Use the CISSP, Luke (was Re: Certifiying Security Auditors)
From: Bennett Todd <bet @ rahul . net>
Date: Fri, 20 Feb 1998 05:46:45 -0800
To: Larry Kwiat <Larry . Kwiat @ gov . yk . ca>
Cc: Anton J Aylward <anton @ the-wire . com>, firewalls @ GreatCircle . COM
In-reply-to: <1 . 5 . 4 . 32 . 19980219224520 . 0093a7e8 @ mailhost . gov . yk . ca>; from Larry Kwiat on Thu, Feb 19, 1998 at 02:45:20PM -0800
References: <1 . 5 . 4 . 32 . 19980219224520 . 0093a7e8 @ mailhost . gov . yk . ca>

1998-02-19-22:45:20 Larry Kwiat:
> >From our discussion, I wonder if you'd admit to having learned anything
> >from anyone.

Maybe not from you, probably not from anyone who would waste time on the
CISSP, but from people who know more than me about computer security,
yes, of course, that's the only way to try to stay up to date in this
field.

> > [ re off-site contingency facilities and their security ]
> > <snip> The access needs are far slimmer, so the security
> >can be cranked down way tighter for a given level of cost and user
> >hassle.
> >
> I don't agree. In many ways, an "exported tech. solution" is much harder to 
> manage well as a security item than one onsite and owned.

What do you mean ``exported tech. solution''? It's a site that we set up
and administer, to which we have physical and network access, with
stricter physical security than our normal office, in-house WAN access
to other offices, and the exact same dialup access w/ security control
as our main site. We set it up, we run it, just the same way we run our
main site --- but since far less access is needed it can enjoy better
physical security, and the comms security is the same.

> Access needs are only a small part of the picture.

Again, what do you mean?

Computer security is a three-way tradeoff. Security, cost, and access
convenience. Reduce the demand for access convenience and you can
increase security for the same cost in $$$ and manpower, it's quite
straightforward.

> I'm afraid that about does it for me. I have other things to do than engage 
> in this. Best of luck in your career.

Oops, by all means ignore this reply, didn't know you were leaving when
I started reading your note. Bye!

-Bennett


References:
Indexed By Date Previous: FREE ADVERTISING!!!
From: centurymkting @ hotmail . com
Next: Re: screened subnet firewall
From: Mario Biron <mario @ almerco . ca>
Indexed By Thread Previous: Re: Use the CISSP, Luke (was Re: Certifiying Security Auditors)
From: Larry Kwiat <Larry . Kwiat @ gov . yk . ca>
Next: Re: Use the CISSP, Luke (was Re: Certifiying Security Auditors)
From: Anton J Aylward <anton @ the-wire . com>

Google
 
Search Internet Search www.greatcircle.com