nCircle.com >> 360 Security

« Has it really been that long? | Main | SCADAGard SIG To Be Established »

Policy Violation or Vulnerability?

it seems that in recent years, nay, the last decade, there has been a tendency for vulnerabilities and policy violations to be lumped together. is having an insecure password, running non-encrypted services such as telnet, or writeable directories via ftpd more of a vulnerability than a violation of policy, or of bad policy?

all of these things, while able to be potentially leveraged to compromise a system, can easily be addressed by applying best practices. wouldn't it be better to call these types of scenarios out in the policy arena?

comments, thoughts, etc.

Comments (1)

bsonne:

I see what you're getting at, but I suspect that the reason they're all lumped together as they are currently is because they are all being considered as vectors for attack. When considering them as vectors for attack I don't think it really matters how you seperate them into classes.

Not that I agree with that, but I think it's a frame of mind that just gets propagated along. I'm not sure that significant enough advantages would be offered by 'calling them out in the policy arena'. It might prove to much effort and paperwork for some people, and as we all know, most people get pretty addicted to the way they think.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on April 8, 2005 5:54 PM.

The previous post in this blog was Has it really been that long?.

The next post in this blog is SCADAGard SIG To Be Established.

Many more can be found on the main index page or by looking through the archives.