Re: Issue 3: replacement boilerplate for managementobjectsensitivity

"Randy Presuhn" <[email protected]>
Newsgroups gmane.ietf.ops
Message-ID <007601c986f6$8bae42e0$6801a8c0@oemcomputer>
Hi -

> From: "David Harrington" <[email protected]>
> To: "'Randy Presuhn'" <[email protected]>; "'ops-area (IETF)'" <[email protected]>
> Sent: Wednesday, February 04, 2009 10:27 AM
> Subject: RE: [OPS-AREA] Issue 3: replacement boilerplate for managementobjectsensitivity
>
> Hi,
> 
> > I prefer the approach of the old text, which split the 
> > information elements
> > according to concern (modification or mere exposure),
> 
> So would this work better?

Yes, I think it's an improvement over the original proposal.

Randy

> -- include this paragraph if the management information can be
> created, deleted, or modified:
> 
>    Some management information defined in this document can be
> created, deleted, or modified by one or more management protocols.
> Unauthorized or inappropriate modification could have a negative
> effect on network operations or security. 
> 
>     <list the sensitive information elements and state why they are
> sensitive to modification>
> 
> -- include the following in all documents that define management
> information:
> 
>    The management information defined in this document can be
> considered sensitive or lead to network vulnerabilities in some
> environments. It is important to control access to this information
> and possibly to encrypt the information when sending the information
> over a network using a management protocol, to prevent unauthorized or
> inappropriate exposure of this information. 
> 
> Following is a list of the potentially sensitive information, and why
> this information is sensitive:
> 
>     <list the sensitive information elements and state why they are
> sensitive to exposure>
>  
> 
> dbh
> 
> > -----Original Message-----
> > From: [email protected] 
> > [mailto:[email protected]] On Behalf Of Randy Presuhn
> > Sent: Wednesday, February 04, 2009 1:17 PM
> > To: 'ops-area (IETF)'
> > Subject: Re: [OPS-AREA] Issue 3: replacement boilerplate for 
> > managementobjectsensitivity
> > 
> > Hi -
> > 
> > > From: "David Harrington" <[email protected]>
> > > To: "'ops-area (IETF)'" <[email protected]>
> > > Sent: Wednesday, February 04, 2009 7:47 AM
> > > Subject: [OPS-AREA] Issue 3: replacement boilerplate for 
> > management objectsensitivity
> > ...
> > > NEW:
> > ...
> > > Following is a list of the potentially sensitive 
> > information, and why
> > > this information is sensitive:
> > > 
> > >     <list the sensitive information elements and state why they
> are
> > > sensitive to modification and exposure>
> > ...
> > 
> > I prefer the approach of the old text, which split the 
> > information elements
> > according to concern (modification or mere exposure), rather than
> > lumping everything together like this, since separating them may
> help
> > in security policy formulation and sanity checking.
> > 
> > Randy
> > 
> > _______________________________________________
> > OPS-AREA mailing list
> > [email protected]
> > https://www.ietf.org/mailman/listinfo/ops-area
> > 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.