Lecture 17: Policy and Management
Date
: November 8, 2013
Homework due
: Nov. 20 at 5:00pm
Midterms: average (mean) was 73
Security policy
Set of rules describing what is allowed and what is not allowed
Soundness, completeness, and precision
In practice, developed to meet specific needs of organization
Developing a policy
Who does this, especially in an organization with multiple organizational units
Requirements analysis
Turning them into policy
Communicating the policy to others
Real-life problems
Policy incompleteness
Dynamic vs. static policies
Incorrect or contradictory policy rules
Management
Ensuring that the policy is carried out correctly
Problems
Enforcement mechanisms may not be able to enforce policy exactly
Policy may be enforced poorly
Policy and/or enforcement mechanisms may conflict with work goals
Users and policy
Are users the enemy?
How are exceptions handled?
Fairness in general
First example: UC and UC Davis email policy
Second example: “Big data”, government and corporate interests, peoples’ interests
You can also obtain a PDF version of this.
Version of November 7, 2013 at 8:21AM