Dave's Bit Bucket

Dave Walker's jottings - mostly pertaining to security


20070123 Tuesday January 23, 2007

"People, policy, procedure..."

It's often said that "security is 70% people, policy and procedure, and 30% what you do to the computers".

This was brought home to me on the train into London this morning, when I sat next to a young lady who was reading a bunch of documents contained in a bulging lever-arch file. The documents had Crown Prosecution Service header pages on them, and appeared to be all the trial documents associated with a rape case - witness statements, forensic reports, the lot.

Some of them were even protectively-marked as RESTRICTED in the header and footer on each page.

I was able to see all the details - names of plaintiff, accused, witnesses etc - as were some folk who got on at the next station and stood next to us.

Sometimes I wonder why we bother with computer security - on the other hand, I wish I had been able to figure out how to get her details, to pass to someone who could get her clearance revoked...

(2007-01-23 07:52:20.0) Permalink Comments [0]

Calendar

« January 2007 »
MonTueWedThuFriSatSun
1
3
5
6
7
8
9
10
12
13
14
16
18
19
20
21
24
25
26
27
28
30
31
    
       
Today

RSS Feeds

XML
All
/Cooking
/General
/Java
/Networking
/Security

Search

Links

Innovate on OpenSolaris

  Read via bloglines :
British Blog Directory.


Navigation



Referers

Today's Page Hits: 298