[ Home | Liste | F.A.Q. | Risorse | Cerca... ]


[ Data: precedente | successivo | indice ] [ Argomento: precedente | successivo | indice ]


Archivio: Luglio 2005 ml@sikurezza.org
Soggetto: RE: [ml] Sicurezza Wireless
Mittente: antonio
Data: Thu,  7 Jul 2005 20:33:49 +0200 (CEST)
Il giorno gio, 07-07-2005 alle 08:27 +0200, marco misitano ha scritto:

> 
> RFC2196:
> 
> (1)  Identify what you are trying to protect.
> (2)  Determine what you are trying to protect it from.
> (3)  Determine how likely the threats are.
> (4)  Implement measures which will protect your assets in a cost-
>      effective manner.
> (5)  Review the process continuously and make improvements each time
>      a weakness is found.

bè visto che ci siamo aggiungerei:

Step 1: What assets are you trying to protect?
Step 2: What are the risks to those assets?
Step 3: How well does the security solution mitigate those risks?
Step 4: What other risks does the security solution cause?
Step 5: What trade-offs does the security solution require?

by Bruce Schneier

Ciao,
Antonio "s4tan" Parata





[ Home | Liste | F.A.Q. | Risorse | Cerca... ]

www.sikurezza.org - Italian Security Mailing List
(c) 1999-2005