Updated: 2.9.2002; 22:17:41 GMT

Security Weblog



daily link  Wednesday, August 14, 2002

Legal issues and security in web services (plus new blog)

Mark O'Neill, CTO of Irish web services security outlet VordelSecure, I mentioned here some time ago, has a brand new weblog. This is also a reminder that I should read technical papers I downloaded from their website.

In his weblog, Mark talks about legal implications of SAML. Legal issues have quite a significant impact on any security design. In a sense, security does not mean protecting systems, but rather protecting business objectives or people' objectives. To achieve this goal, good security needs to consider an issue of liability. This means that it is not enough to find out what the risks are and how to protect against them, but also to consider who would be held liable should anything go wrong.  When security fails (provided the incident is discovered) you can bet that somebody will need to take the blame. Serious incidents can lead to lawsuits. To certain a limit, you can reduce this risk through appropriate use of technology.  To a certain extent, you can transfer the risk to other parties through legal means. On some occasions, this can be a better approach than to design unusable or technically difficult technical solution.

Talking about legal issues, some time ago I came across presentations on legal issues and on security from an Object Management Group's workshop on web services.

  6:25:10 PM  permalink  

 
August 2002
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Jul   Sep
General

About
Reading list
Resources
Contact me

News

SANS NewsBites
Crypto-gram
UKCrypto
Information Security
all.net
Objectwatch
CBDi Forum

Channels

RSS Better Living Through Software
RSS Brent Sleeper: Web Services
RSS David Fletcher's Government and Technology Weblog
RSS DeveloperWorks.com - Security Articles
RSS Dictionary.com Word of the Day
RSS Digital Identity
RSS Digital Identity World
RSS Eric J. Norlin's Blog
RSS IBM Developer Works - Web Architecture Articles
RSS Joel on Software
RSS Jon's Radio
RSS KableNET
RSS Loosely Coupled weblog
RSS Mark O'Neill's Radio Weblog
RSS O'Reilly Network Articles
RSS onlineblog.com
RSS Scott Loftesness: Digital Identity
RSS Scott Loftesness: Trusted Computing
RSS Scripting News
RSS Security Blog
RSS SecurityFocus
RSS Web Services Architect
RSS Web Services Articles from The Stencil Group
RSS WebServices.Org
RSS Windley's Enterprise Computing Weblog



Click to see the XML version of this web page.

jenett.radio.simplicity.1.3R
Radio Userland



Copyright 2002 © Jiri Ludvik.
Last update: 2.9.2002; 22:17:41.