T. E. Gray
03 Oct 2003

Security at the UW

Security is:

Essential to:

Elusive and Expensive because:

Expectations for the network are rising and conflicting:

Lessons learned already:

We need to change the way UW approaches security:

We cannot do it just centrally. We could make some inroads if we had the resources (scanning, assessments, consulting, training, awareness).
It is expensive. We have no choice.


Seven Security Axioms

  1. Network security is maximized when we assume there is no such thing.
  2. Large security perimeters mean large vulnerability zones.
  3. Firewalls are such a good idea, every computer should have one. Seriously.
  4. Remote access is fraught with peril, just like local access.
  5. One person's security perimeter is another's broken network.
  6. Isolation strategies are limited by how many PCs you want on your desk.
  7. Network security is about psychology as much as technology.
Bonus: never forget that computer ownership is not for the feint-hearted.


Technical Recommendations

For Desktops:

For Servers:



TEG HOME