Re: New 6.1 security group ptf.
CRPence <CRPbottle-/[email protected]> Tue, 02 Jun 2009 13:25:05 -0400
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Organization | midrange.com |
| Message-ID | <[email protected]> |
John Jones wrote: > There may also be shops that have internal controls, procedures, > and/or audit requirements that allow security updates but not > necessarily any other updates without rigorous review & testing. > Having a separate security group lets them get those updates > without scouring all PTF cover letters looking for just > security-related events. FWiW. The security\integrity PTFs [for LIC, OS, and LPPs] had already been included with the HIPer designation and each identified with variant(s) of the "security" and "integrity" terms capable of being found with a simple token search; i.e. no poring over cover letters required to locate them. Issues which either effect data errors per designation of "incorrect output" or defects which may result in system failure, in many cases would be much more important to include in the list of updates being installed [in consideration of the cover letter text, for how the described situation might be applicable], than those of a security nature [for which no description of what either the defect or its correction is published for which just as rigorous testing would be justified but without full ability to review]. Regards, Chuck _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.