Educause Security Discussion mailing list archives

Re: Spaf did not receive your email (was Re: Job Descriptions)


From: "Bruhn, Mark S." <mbruhn () INDIANA EDU>
Date: Wed, 26 Feb 2003 17:57:25 -0500

This is an age-old discussion and issue -- not whether security people
should personally boycott MS products, which I suppose we could discuss
as well, but whether we should (and in fact can, given alternatives)
actively attempt to influence our communities to avoid MS products.
More discussion on this list would be quite interesting, esp. if it
leads to something actually useful in this contentious space.

In a perfect world, all systems would be secure (or there wouldn't be a
need to secure them), and I could be running a restaurant right now.  

I'm sure someone knows the statistics -- I would guess 65% of our
community use Windows and MS products.  We can certainly grouse about
that and strongly encourage them to use something else (What?  Someone
could start by listing the suite of products that equate), but the
reality is that they are not going to stop using that suite of
applications, and we're going to have to spend time on helping them
secure them.  

As an aside, is there a way to configure my Outlook client (clearly I'm
in that 65%) to NOT let me send .doc files?  :-)
 
M.

-- 
Mark S. Bruhn, CISSP
Chief IT Security and Policy Officer
Office of the Vice President for Information Technology and CIO
Indiana University
812-855-0326

Incidents involving IU IT resources: it-incident () iu edu
Complaints/kudos about OVPIT/UITS services: itombuds () iu edu




-----Original Message-----
From: Kevin Shalla [mailto:Kevin.Shalla () IIT EDU] 
Sent: Wednesday, February 26, 2003 10:18 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Spaf did not receive your email (was Re:
[SECURITY] Job Descriptions)


I can't help but jump in here.  As leaders in security, shouldn't we
strive
to behave uncommonly if by doing so we can improve security, and also
set a
good example?  On the other hand, maybe we don't all agree that it is
preferable to not send Word documents.  I do agree with Gene Spafford
that
stamping out certain types of email attachments would drastically reduce
many problems we do have today.
At 08:15 AM 2/26/2003 -0500, you wrote:
Spaf, your opinion in this area is well known, certainly.  Common may
not mean standard, but common does mean common.

Most of the documents I sent (and send) happen to be in Word format in
our repository, and rarely does someone I send them to have trouble
dealing with the format.  So, I suspect that anyone who is interested
in
the documents I sent and needs them in a different format will ask me.
If I had sent them in response to a request from you, I certainly would
have sent them in rtf  :-)

M.

--
Mark S. Bruhn, CISSP
Chief IT Security and Policy Officer
Office of the Vice President for Information Technology and CIO
Indiana University
812-855-0326

Incidents involving IU IT resources: it-incident () iu edu
Complaints/kudos about OVPIT/UITS services: itombuds () iu edu




-----Original Message-----
From: Gene Spafford [mailto:spaf () CERIAS PURDUE EDU]
Sent: Tuesday, February 25, 2003 7:03 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Spaf did not receive your email (was Re:
[SECURITY] Job Descriptions)


Sorry, folks.   I guess I need to adjust the filter on my autoreply.

    ....and security people need to learn not to send Word documents!

**********
Participation and subscription information for this EDUCAUSE Discussion
Group discussion list can be found at
http://www.educause.edu/memdir/cg/.

**********
Participation and subscription information for this EDUCAUSE Discussion
Group discussion list can be found at
http://www.educause.edu/memdir/cg/.


Kevin Shalla
Manager, Student Information Systems
Illinois Institute of Technology
<mailto:Kevin.Shalla () iit edu>

**********
Participation and subscription information for this EDUCAUSE Discussion
Group discussion list can be found at
http://www.educause.edu/memdir/cg/.

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/memdir/cg/.

Current thread: