> But things always go wrong in large IT shops.

True... but it's useful to try and limit those failures to new and fun
events, as opposed to basic stuff that's in "Secure site design 101",
because failures of that nature when you are as high profile as Citibak
would likely indicate failures on multiple fronts: vetting design firms,
defense in depth implementation, pen-testing, etc...

-sc

> -----Original Message-----
> From: Ken Schaefer [mailto:[email protected]]
> Sent: Wednesday, June 15, 2011 8:17 AM
> To: NT System Admin Issues
> Subject: RE: [OT] Citibank worse at security than Sony
> 
> You can push all you like. But it's not your area of expertise. So you
rely on
> other people to tell you that the app works well. Things will always
still slip
> through the cracks.
> 
> I'm not trying to excuse this - it looks pretty amateurish. But things
always go
> wrong in large IT shops.
> 
> -----Original Message-----
> From: Ben Scott [mailto:[email protected]]
> Sent: Wednesday, 15 June 2011 7:55 PM
> To: NT System Admin Issues
> Subject: Re: [OT] Citibank worse at security than Sony
> 
> On Wed, Jun 15, 2011 at 7:39 AM, Ken Schaefer <[email protected]>
> wrote:
> > Hmm - at the individual application development level, in a large
org,
> > no one cares about shareholder value.
> 
>   That's why the people at the top need to be the ones pushing for
security.
> It can't be driven from the bottom.
> 
> 
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~
> <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
> 
> ---
> To manage subscriptions click here: http://lyris.sunbelt-
> software.com/read/my_forums/
> or send an email to [email protected]
> with the body: unsubscribe ntsysadmin


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to