NoShut.com Home NoShut.com
Alan Expressions
Insightful, delightful and entertaining some of the time.
September 2010
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    
< Aug   Oct >

[Recent Entries]
[Entry Index]

Recent Entries
Topics
Other Blogs
Powered by PolarBlog
RSS 2.0 Feed

Valid CSS!
Valid XHTML 1.0!
Valid RSS!
Topic: Technology   Three+ Things I learned at SANS 2010 Today
01:24AM March 9, 2010
Three+ things I learned at SANS 2010 (Legal Track) today:
1. Appropriately vague or tentative language is not a bad thing in security policies. What is the risk of writing a “must” into a policy, not delivering on the promise, then having to testify about your lack of enforcement in court or answer to it in a public forum?

2. Any effort to provide due care is better than no effort at all (e.g. having a security policy vs. not having one due to lack of enforcement concerns). Negligence when common sense states that there was a easy solution is bad - especially to a judge or jury.

3. Disclaimers, Terms of Service, and things like login banners should be used whenever possible. Words are cheap, and can save your ass. The key concept is to seek consent so that you can handle privacy concerns.

4. Handling a legal issue in the wrong way can turn into a PR nightmare. Decisions to take legal action should be ran through a PR filter to make sure it won’t stink when your opponents take their argument to the Internet.

Great class so far, loving the material and providing new perspectives.

Tuesday Edition
Main Blog
[Permalink]   [Google]   (202 Words)

Topic: