Updated: 2.9.2002; 22:17:42 GMT

Security Weblog



daily link  Sunday, August 18, 2002

"Who owns what" and other amusing questions

Over the weekend I found some time to had a look at presentations from the OMG conference I had found out about last week. In a presentation from a guy named Matt Hettinger I have found out excellent compilation of questions that go straight to the heart of many security issues in multi-organisation IT deployments.

  • What is the nature of the relationship between enterprises doing business?
  • Degree of coupling and coherency?
  • What is the degree of trust?
  • What are the boundaries between enterprises?
  • Who owns what?  What are the expections placed on each enterprise doing business with each other?
  • What kind of liability risks are there?
  • At what points, in the process of doing business, is there a liability risk to each enterprise?
  • Are there shared risks?
  • Who’s accountable?
  • What processes can be put in place to ensure quality of service expections are met?

Some of the questions are rather obvious, but can be hard to answer as the size of the organisation involved grows and their governance gets poorer. Have quite a few horror storries with "who owns what" from the time when I was doing some work for government. One agency initially financed infrastructure that later on became shared and relied upon for day-day operations by half dozen of others. Lacking people to run the infrastructure, not claiming accountability, but using initial investment as a leverage in political infights with others meant that otherwise intelligent insiders had real difficulty answering to the simple question of "who owns what". In the end we had about three different "ownerhips" covering organisational, operational and political angles.

  10:04:55 PM  permalink  

 
August 2002
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Jul   Sep
General

About
Reading list
Resources
Contact me

News

SANS NewsBites
Crypto-gram
UKCrypto
Information Security
all.net
Objectwatch
CBDi Forum

Channels

RSS Better Living Through Software
RSS Brent Sleeper: Web Services
RSS David Fletcher's Government and Technology Weblog
RSS DeveloperWorks.com - Security Articles
RSS Dictionary.com Word of the Day
RSS Digital Identity
RSS Digital Identity World
RSS Eric J. Norlin's Blog
RSS IBM Developer Works - Web Architecture Articles
RSS Joel on Software
RSS Jon's Radio
RSS KableNET
RSS Loosely Coupled weblog
RSS Mark O'Neill's Radio Weblog
RSS O'Reilly Network Articles
RSS onlineblog.com
RSS Scott Loftesness: Digital Identity
RSS Scott Loftesness: Trusted Computing
RSS Scripting News
RSS Security Blog
RSS SecurityFocus
RSS Web Services Architect
RSS Web Services Articles from The Stencil Group
RSS WebServices.Org
RSS Windley's Enterprise Computing Weblog



Click to see the XML version of this web page.

jenett.radio.simplicity.1.3R
Radio Userland



Copyright 2002 © Jiri Ludvik.
Last update: 2.9.2002; 22:17:42.