Re: New 6.1 security group ptf.

CRPence <CRPbottle-/[email protected]> Tue, 02 Jun 2009 13:25:05 -0400
Newsgroups gmane.comp.systems.as400.security
Organization midrange.com
Message-ID <[email protected]>
John Jones wrote:
> There may also be shops that have internal controls, procedures,
> and/or audit requirements that allow security updates but not
> necessarily any other updates without rigorous review & testing.
> Having a separate security group lets them get those updates
> without scouring all PTF cover letters looking for just
> security-related events.

   FWiW.  The security\integrity PTFs [for LIC, OS, and LPPs] had 
already been included with the HIPer designation and each identified 
with variant(s) of the "security" and "integrity" terms capable of 
being found with a simple token search; i.e. no poring over cover 
letters required to locate them.  Issues which either effect data 
errors per designation of "incorrect output" or defects which may 
result in system failure, in many cases would be much more important 
to include in the list of updates being installed [in consideration 
of the cover letter text, for how the described situation might be 
applicable], than those of a security nature [for which no 
description of what either the defect or its correction is published 
for which just as rigorous testing would be justified but without 
full ability to review].

Regards, Chuck
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.