[aklug] Re: Information Systems Audit

From: Marc Grober <marc@interak.com>
Date: Wed Feb 06 2013 - 12:22:31 AKST

Since old farts are opining....

On Feb 6, 2013, at 11:05 AM, Arthur Corliss <acorliss@nevaeh-linux.org> wrote:

> Leaving security & auditing to the programmers would be a horrible mistake.

Security is a matter of philosophy, not science and engineering in a sense is anathema to an adequate appreciation of the subject. A firm I worked actually paid for a security analysis, which simply ignored a hole that, as I suggested to the IA, a high school kid could back a van through.

SAs are invariably (and rightly) cast as Zeno's Achilles, and while that is no reason to throw in the towel and get in the tub with Archimedes, lol, it should give one pause to ponder.....---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Wed Feb 6 12:22:43 2013

This archive was generated by hypermail 2.1.8 : Wed Feb 06 2013 - 12:22:43 AKST