Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
google site



Closed Thread
English Japanese Spanish French German Portuguese Italian Powered by Powered by Google
 
Search this Thread
  #1  
Old 12-08-2009
Linux Bot's Avatar
Forum Robot Girl
 

Join Date: Sep 2000
Posts: 24,458
Thanks: 0
Thanked 6 Times in 6 Posts
The Risks of Bad Communication

I have been thinking about whether there are are any risks unique toremote facilities when it comes to a company's IT security design. This could be locations in different cities, near-shoring, off-shoring,etc.

From the article Bad Communication Can Create Risk, the author lists four risks mitigated by effective communication:
  • Increased employee resignations
  • Decreased employee productivity
  • Overt employee subversion
  • Inability to achieve company goals
From an IT security perspective, I will add:
  • Back doors
  • Data leakage
  • Malicious behavior (unintentional or otherwise)
The knowledge of being observed is itself a deterrent to bad behavior.  There is the Observer (or Hawthorne) effect,which "refers to changes that the act of observing will make on thephenomenon being observed."  Distance or separation from the companycould reduce efficacy of this control, and may embolden a subversivecontractor or employee.

Also, with a lack of proximity to the end users, you have no choice butto make assumptions to fill in the gaps during the requirementsgathering phase.  Like in Jurassic Park where the  geneticists filledgaps in the DNA with frog DNA:  we know how that turned out.  If thedesign proceeds on incomplete information, mistakes will undoubtedly bemade.  Architectural and security decisions should not be based on whatis "believed" to be the environment and usage behavior of a distantlocation.  The risk is that you may proceed with a false sense ofsecurity because the design and implementation are based on a false setof premises. 

There are also language and translation challenges, as well as timezone differences.  These factors can add layers of confusion andmisinformation, and can be additional challenges to effective security(see the four risks above).  Miscommunication could also lead users tounintentionally break security rules because they are not fullyunderstood, and because monitoring is not in full effect, the behaviorgoes on unnoticed.

Distance and communication challenges should inform the securitydesign.  Assumptions, due to lack of communication or sheerexasperation, should be kept to a minimum.  This may require a fewtrips to the distant location, as well as establishing a mechanism tovirtually visit (e.g. WebEx, video conference) the location on aregular basis.  The first step to good security is to candidly identifythe differences between a remote and home location, and to designaccordingly.




More...
Sponsored Links
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Treating risks Linux Bot IT Security RSS 0 07-27-2009 05:30 AM
The Top Information Security Risks for 2008 Linux Bot Complex Event Processing RSS News 0 01-15-2008 09:20 AM
Communication Failures barun agarwal HP-UX 1 10-01-2007 08:48 AM
help on network communication Deanne Solaris 3 05-11-2007 11:46 AM
chmod 777 security risks? Gary777 UNIX for Dummies Questions & Answers 6 11-23-2006 10:42 AM



All times are GMT -4. The time now is 12:13 AM.