Re: Security testing: need for a security policy, and a security-critical package process

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



gene@xxxxxxxxx said:
...
> A written description of the security policy is a must!
...

Is the idea of a single one-size-fits-all security policy reasonable?  I 
think Fedora has a broad range of users.

Security is a tradeoff.  If you make it impossible for the bad guys to get 
in, the good guys probably can't get any work done.  How secure do you need 
to be?  How much are you willing to pay for it?

I'd much rather have an overview document that explains the likely attacks 
and potential solutions, and their costs and benefits.  Additionally, I think 
it's much easier to follow a policy if I understand the reasonaing behind it.

I think sample policy documents with descriptions of their target audience 
and checklists for how to implement them would be helpful.



-- 
These are my opinions, not necessarily my employer's.  I hate spam.



--
Fedora-security-list mailing list
Fedora-security-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-security-list

[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Coolkey]

  Powered by Linux