I'm not talking in the office users, but developers home machines.

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] 
Sent: Monday, January 27, 2003 6:40 AM
To: NT 2000 Discussions
Subject: RE: SQL worm?


On Mon, 27 Jan 2003, at 6:07am, [EMAIL PROTECTED] wrote:
> Here is an example "I'm a programmer and need SQL on my PC to do my job".
> Unfortunately the rest goes like this "I don't know sh*t about security or
> this patching stuff, so I will just go on my happy way in ignorance"

  The best way to do it is to have the PC controlled, or at least
supervised, by the IT staff.  That way the programmer gets to live in happy
ignorance, while the system is still reasonably well maintained.

  Of course, that's not always possible, especially if the programmer is
doing more than just simple SQL hacking.  In that case, put the PC in a lab,
behind an interior firewall, and heavily isolate it from the rest of the
network.  Maybe he needs two PCs that way, but that's the cost of
development.

-- 
Ben Scott <[EMAIL PROTECTED]>
| The opinions expressed in this message are those of the author and do  |
| not represent the views or policy of any other person or organization. |
| All information is provided without warranty of any kind.              |


------
You are subscribed as [EMAIL PROTECTED]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to %%email.unsub%%

------
You are subscribed as [email protected]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to [EMAIL PROTECTED]

Reply via email to