<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Vulnerabilities of low probability bring about devestating impact</title>
	<link>http://www.tssci-security.com/archives/2007/05/17/vulnerabilities-of-low-probability-bring-about-devestating-impact/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Sat, 05 Jul 2008 20:32:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Marcin</title>
		<link>http://www.tssci-security.com/archives/2007/05/17/vulnerabilities-of-low-probability-bring-about-devestating-impact/#comment-656</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Fri, 18 May 2007 03:42:48 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/05/17/vulnerabilities-of-low-probability-bring-about-devestating-impact/#comment-656</guid>
		<description>LV, data classification has been a lost cause everywhere I've seen it tried. People begin to classify data, or have develop some plan; then over a couple years it dies away and a new initiative is introduced which is totally different bringing you right back to square one.

The reason why the government gets it right with classifying data is because there's an actual incentive too... starting with one year in jail!</description>
		<content:encoded><![CDATA[<p>LV, data classification has been a lost cause everywhere I&#8217;ve seen it tried. People begin to classify data, or have develop some plan; then over a couple years it dies away and a new initiative is introduced which is totally different bringing you right back to square one.</p>
<p>The reason why the government gets it right with classifying data is because there&#8217;s an actual incentive too&#8230; starting with one year in jail!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://www.tssci-security.com/archives/2007/05/17/vulnerabilities-of-low-probability-bring-about-devestating-impact/#comment-655</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Fri, 18 May 2007 00:05:23 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/05/17/vulnerabilities-of-low-probability-bring-about-devestating-impact/#comment-655</guid>
		<description>You hit a ton of info and issues in this one post! Yikes!

Interesting about ssh port forwarding and what is basically looking at covert channels. I'd love to work in a larger campus and get a chance to play with mitigating those issues on the network.

Data classification....man. The only place that does this well is the gov't, and really only because they've been doing it for many, many decades. Even smaller companies like mine find it impossible to try to classify and protect data and get mgmt buyin and employee support for it. I can't even imagine it in a larger company. We can do a lot of lip service the "analyst way" by spouting best practices and we can try to make a dent, but I really truly believe no company has a handle on their data except in maybe a very broad stroke. "Uhh, everything is classified," or "All emails should not be considered private..." and other such nonsense that isn't accurate anyhow. Unless someone is looking at and classifying the data manually to some high degree or users are accurately classifying their own information, it's just not gonna happen. Besides, companies have their product and their profits to worry about and spend money on... :(

Hell, it's hard enough to get people to delete shit let alone classify it properly. It's crazy how much information clogs up the network devices and backups and systems like so much cholesterol in a McDonald's junky. :(</description>
		<content:encoded><![CDATA[<p>You hit a ton of info and issues in this one post! Yikes!</p>
<p>Interesting about ssh port forwarding and what is basically looking at covert channels. I&#8217;d love to work in a larger campus and get a chance to play with mitigating those issues on the network.</p>
<p>Data classification&#8230;.man. The only place that does this well is the gov&#8217;t, and really only because they&#8217;ve been doing it for many, many decades. Even smaller companies like mine find it impossible to try to classify and protect data and get mgmt buyin and employee support for it. I can&#8217;t even imagine it in a larger company. We can do a lot of lip service the &#8220;analyst way&#8221; by spouting best practices and we can try to make a dent, but I really truly believe no company has a handle on their data except in maybe a very broad stroke. &#8220;Uhh, everything is classified,&#8221; or &#8220;All emails should not be considered private&#8230;&#8221; and other such nonsense that isn&#8217;t accurate anyhow. Unless someone is looking at and classifying the data manually to some high degree or users are accurately classifying their own information, it&#8217;s just not gonna happen. Besides, companies have their product and their profits to worry about and spend money on&#8230; :(</p>
<p>Hell, it&#8217;s hard enough to get people to delete shit let alone classify it properly. It&#8217;s crazy how much information clogs up the network devices and backups and systems like so much cholesterol in a McDonald&#8217;s junky. :(</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.188 seconds -->
