Firewall Wizards mailing list archives

Re: What's in a security policy? (was Re: How do we do our job?)


From: darrenr () reed wattle id au
Date: Thu, 30 Apr 1998 23:47:57 +1000 (EST)

In some email I received from Bennett Todd, sie wrote:

But none of this comes near addressing the point you raised: how would
you go about ``verifying that a security policy is any good''?

Well, the first step might be to check that it actually exists.

The next might be to evaluate it against what the business requires from
whatever it controls and what the security risks are.

Darren



Current thread: