Re: Who stay focused? (was: [Fwd: Question])
ArkanoiD <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Well, i guess role-based data control and entitlement management is something that can (applying necessary frameworks like WS-* and embedding security tokens into all data flow both in- and intersystem) change the security landscape. If it ever will be applied properly. I doubt so. On Mon, Apr 20, 2009 at 04:53:02PM +0530, Devdas Bhagat wrote: > > > up on any workgroups or technical commetees, they do not invent and more, > > they do not really have a clue to stay on the leading edge (how > > ridiculously does it sound when applied to our pretty conservative field, > > That depends on what bits of infosec you consider bleeding edge. For > most applications, the security rules are fairly well known and attacks > don't change all that often. > > If you can't fix the holes, and bandages don't work very well, you have > to give up and work on where you can make a change. My current areas of > focus are on outbound filtering (rather than inbound) and education. > Applying Postel's law to networks and networked applications is useful. >