The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
missing CDE frankkahle SUN Solaris 5 05-25-2006 05:35 PM
what am I missing? Zelp Shell Programming and Scripting 4 06-13-2005 05:32 PM
/tmp is missing ???? BAM UNIX for Dummies Questions & Answers 1 11-05-2002 02:50 PM
/dev/fb* missing heinb UNIX for Dummies Questions & Answers 5 02-12-2002 05:22 AM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 05-04-2009
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 21,977
The Missing Vials

Last month, it was reported that "three small vials of Venezuelan equine encephalitis virus weredetermined to have been unaccounted for last year."  While it has beenconcluded that this was not the result of misconduct, it does raise questions about the risk of mishandling sensitivematerials.  An act of theft was not detected; the absence of thingsinferred theft.  So this demonstrates an administrative type of risk,where alarms are sounded and must be responded to due to properinventory controls not being used, or used improperly.

An article in Wired magazine sums it up nicely:  "Biological material can be grown, and on the other hand, it can dieoff. So what happens if the bugs in a few test tubes die off, and thescientist just shrugs and cleans them out without noting the action inhis lab books? A few years later, and people wonder, what happened tothe material in test tubes 45-48?"  Following an adequate inventory control process could prevent this type of mishap.

A short list of activities that need to be conducted as a result of this panic:
  • Interviews and interrogations
  • Review of logs and accesses
  • Full inventory audit
Then there is the public relations impact.  If something of this scopeleaked out for a company, how much would this cost in terms of loss oftrust and customers?  The Army being a government entity, this type of incident hasthe potential impact of increased anxiety and fear for the public,which could significantly affect the nation's productivity (which hasits own price tag.)

Some recommendations for things to do regularly and thoroughly:
  • Audit inventory
  • Review and test security controls
  • Review checkout processes
My point is, it doesn't always take an attack to cause a major securityincident.  Sensitive material that cannot be accounted for may beassumed to be in someone else's hands, and if this is the case, thesafe default position to take may be to assume that the missingmaterial is in the hands of a threat agent.  The reaction may beappropriate (since these is an actual biological virus we are talkingabout) but might have been avoided altogether if inventory, controlsand processes were reviewed regularly and thoroughly.  They say theinsider threat is the biggest threat, and in this case it may have beenjust an internal administrative faux pas that caused a very public security incident.




More...
Sponsored Links
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 07:21 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language translation by Google.
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0