Amazon

Bio

  • David Rice is an internationally recognized information security professional and an accomplished educator and visionary. For a decade he has advised, counseled, and defended global IT networks for government and private industry.

    David has been awarded by the U.S. Department of Defense for “significant contributions” advancing security of critical national infrastructure and global networks. Additionally, David has authored numerous IT security courses and publications, teaches for the prestigious SANS Institute, and has served as adjunct faculty at James Madison University. He is a frequent speaker at information security conferences and currently Director of The Monterey Group.

Blog powered by TypePad

The views and opinions expressed are those of the author and do not reflect the official policy, position, or recommendations of the author's affiliations, partners, employers, or clients.

« New State Data Breach Laws Wrong | Main | 2008: The Year of Crash Test Dummies »

April 01, 2009

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e54f9408a3883401156fb148a4970b

Listed below are links to weblogs that reference Hold Them to a Higher Standard:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Kyle Maxwell

Common Criteria provides a different set of criteria for security. The criteria are still useful, but in a wholly separate way, as it's an entirely different model of managing roles, abilities, and data access. I know this is old news to you, but I suspect most readers of SDTimes don't understand that.

The question of software security applies across all of this, of course, and is still one of the "wicked problems" affecting our entire information infrastructure.

The comments to this entry are closed.