Archives
- ► 2012 (8)
- ► 2011 (157)
- ► 2010 (174)
- ► 2009 (12)
Which topics would you like us to cover more?
Latest comments
- How to reset you Kindle
3, eve...
Thanks for this article and the related "Inside th...
By H K - How to reset you Kindle
3, eve...
How do you drain power on the board? I dont have r...
By Grace - How to reset you Kindle
3, eve...
You're welcome!
By Bas - How to reset you Kindle
3, eve...
Thanks man....removing the battery worked like a c...
By DaveMan - nHapi
example
Hi Slypete, Thank you for your comment. This way w...
By Bas - nHapi
example
Hello, Employing .Net dynamics, one can implement ...
By slypete - Implementing MLLP in C#
Hi Mayura, I'm not sure I understand your question...
By Bas - Implementing MLLP in C#
I have used SSL stream to secure the MLLP transact...
By Mayura
Latest tweets
| The security dilemma revisited. |
| Written by Division by Zero |
| Tuesday, 16 March 2010 09:58 |
|
A while ago I wrote about the security dilemma. I think it's time to put this dilemma in a broader perspective. I changed the triangle I've used to reflect this context.
The dilemma given in my earlier post still stands, but the new perspective changes things. Security isn't only your problem or the problem of the application you build. Security depends ont the position your application has in the complete landscape. Each "building block" in this landscape has it's own security risk to handle, as you have to. But it's the complete picture that has to be secure enough to lower the risk to the organisation. Besides the organisation has their own responsibility towards
security. The choice between user friendliness, functionality and
security is a business decision in the end (yes... we have to give
our advise). The policies of an organization are abstractions of
the truth. They are the way an organisation chooses to see the
world and to react to this world. This vision of the world is
leading for the structure of our application landscape, which
should support the businessmodel and processes. And the application
landscape determines the rules and regulations we have to follow
and what our position in it is. Does this mean we are surrendered to outer side forces? Well... I whish I could say no. But, yes.... we are... partly. But this doesn't mean we should sit back and wait for the world (or in this case, the organisation) to change. We can actively adopt world standards, do whatever we can to make our applications secure enough and try to convince our customer if we need to. By starting discussions about security issues we raise awareness. This is a good starting point, the world doens't change overnight. Tags:
|
Beware of bugs in the above code; I have only proved it correct, not tried it. - Donald E. Knuth






Comments
Does a customer really want security?
Ok let's think aloud.
I can only see disadvantages like costs, time and it's difficult to understand.
Imagine that I'm a bank... what do I really want? Privacy for me and for my customers, always be up and running adn so on..
From that view regarded: Is security not a 'thing' of and for IT people? Isn't security 'just' enforcing the desired wants for a customer, like privacy, reliability etc?
So...in fact I get security for 'free' if I sell the right things? It can not be that easy!
Now I come to the point that I'm with my IT fellows... convincing them is yet an another challange.....
RSS feed for comments to this post