More (Hopefully) Useful Questions
Posted by Ed in Analysis on Jan 25, 2007
Last week, Ross Brown posted his Four Questions to Improve Security over on the Technobabylon blog. I highly recommend checking out the post if you haven’t done so already. Now, Ross’ questions were targeted toward vendors to help vendors (i.e. they are questions to help a potential customer improve the security of their environment.) Anyway, so you have it without having to go to the original post (although I recommend that you do), his questions were:
1) How are you protecting the network?
2) How are you protecting applications and data?
3) How are you protecting systems?
4) How do you know how you are doing?
Now, these are useful in the context of vendor-client interaction. However, within the enterprise itself, I am oftentimes surprised at the questions that practitioners don’t ask themselves. Like:
1) What does the business I support do? And how do I know when they do something that impacts security?
2) Who are my vendors and how do I make sure they handle security appropriately?
3) Where does the data come from and where does it go?
And so on. Very often, I meet individuals in industry tasked with protecting data, tasked with securing resources, and tasked with protecting assets who don’t have answers to these questions. Although I’m not sure that it’s appropriate for a vendor to ask them (and therefore probably not appropriate for inclusion in Ross’ list), I do think somebody should be asking these things.
-
http://www.securityviews.com Scott Wright


