|
Firewalls (February 1994) |
You need a security policy with risk assessment and threat analysis. Then you have something to bargain with -- i.e., when security practices and business requirements clash, it is a basis to get together and decide on changes, either in security policy or business practices. What's the threat? What are you protecting? What is the risk of unrestricted outgoing ftp, etc.? Fred References:
|