<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4391522908329730957.post1545767919699374951..comments</id><updated>2008-06-24T11:26:10.823-04:00</updated><title type='text'>Comments on Data-Centric Protection and Management: The "IT admin bad guy"? Not sure I buy it much..</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.bitarmor.com/feeds/1545767919699374951/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default'/><link rel='alternate' type='text/html' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html'/><author><name>Manu Namboodiri</name><uri>http://www.blogger.com/profile/16254830889604237082</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4391522908329730957.post-5237614644643042868</id><published>2008-06-24T11:26:10.823-04:00</published><updated>2008-06-24T11:26:10.823-04:00</updated><title type='text'>Meta-data is any data describing the policies of w...</title><content type='html'>Meta-data is any data describing the policies of what can be done with the data - this can be protected via integrity checks. Not that hard. &lt;BR/&gt;&lt;BR/&gt;The hard part is getting the policies to "persist" with the data itself - and this is the key. If you can track and enforce policies that remain with the data regardless of where it goes and rests, now we are getting somewhere. &lt;BR/&gt;&lt;BR/&gt;And these policies can also have fine grained ACLs which can deny IT admins the rights - while allowing content owners to access it. All the while integrating with a robust and integrity checked log/audit trail.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/5237614644643042868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/5237614644643042868'/><link rel='alternate' type='text/html' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html?showComment=1214321170823#c5237614644643042868' title=''/><author><name>Manu Namboodiri</name><uri>http://www.blogger.com/profile/16254830889604237082</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16091459826524583520'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html' ref='tag:blogger.com,1999:blog-4391522908329730957.post-1545767919699374951' source='http://www.blogger.com/feeds/4391522908329730957/posts/default/1545767919699374951' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4391522908329730957.post-987998971537925853</id><published>2008-06-24T11:05:55.900-04:00</published><updated>2008-06-24T11:05:55.900-04:00</updated><title type='text'>Manu,We do not use meta-data. We rank code, device...</title><content type='html'>Manu,&lt;BR/&gt;&lt;BR/&gt;We do not use meta-data. We rank code, devices and users for integrity and enforce at the kernel level. If you rank code higher for integrity, than all users, including the security officers and admins, then no one can alter code.&lt;BR/&gt;&lt;BR/&gt;Let me ask you this? What governs the meta-data? How do you know that it is not being altered? Do you have a secondary infrastructure just for this? Actually, integrity rankings can be used here as well.&lt;BR/&gt;&lt;BR/&gt;The thing most people do not consider is that meta-data is a potential covert channel in itself. It is only one way to do things.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/987998971537925853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/987998971537925853'/><link rel='alternate' type='text/html' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html?showComment=1214319955900#c987998971537925853' title=''/><author><name>Rob Lewis</name><uri>http://www.googgun.com</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html' ref='tag:blogger.com,1999:blog-4391522908329730957.post-1545767919699374951' source='http://www.blogger.com/feeds/4391522908329730957/posts/default/1545767919699374951' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4391522908329730957.post-6259934931298909438</id><published>2008-06-24T08:39:25.425-04:00</published><updated>2008-06-24T08:39:25.425-04:00</updated><title type='text'>Rob - agree absolutely. I do think a log and audit...</title><content type='html'>Rob - agree absolutely. I do think a log and audit trail is absolutely critical. &lt;BR/&gt;&lt;BR/&gt;In an information-centric or data-centric world, the protection and audit policies are part of the data (or meta-data if you will) and this makes it easier to track, audit and more importantly deter bad behavior...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/6259934931298909438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/6259934931298909438'/><link rel='alternate' type='text/html' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html?showComment=1214311165425#c6259934931298909438' title=''/><author><name>Manu Namboodiri</name><uri>http://www.blogger.com/profile/16254830889604237082</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16091459826524583520'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html' ref='tag:blogger.com,1999:blog-4391522908329730957.post-1545767919699374951' source='http://www.blogger.com/feeds/4391522908329730957/posts/default/1545767919699374951' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4391522908329730957.post-1008456217045531892</id><published>2008-06-23T23:20:10.368-04:00</published><updated>2008-06-23T23:20:10.368-04:00</updated><title type='text'>Two comments:If one thinks in terms of information...</title><content type='html'>Two comments:&lt;BR/&gt;&lt;BR/&gt;If one thinks in terms of information-centric security or even multilevel security, IT people can retain system and network privileges to maintain networks without having access to data in work groups.&lt;BR/&gt;&lt;BR/&gt;The greatest tool to prevent insider abuse in the tamper proof audit trail.&lt;BR/&gt;People with access are authorized to use that data for only certain things. If an authorized user attempts an unauthorized use of the data, he will hang himself by the audit trace that can not be altered to cover one's tracks.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/1008456217045531892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4391522908329730957/1545767919699374951/comments/default/1008456217045531892'/><link rel='alternate' type='text/html' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html?showComment=1214277610368#c1008456217045531892' title=''/><author><name>Rob Lewis</name><uri>http://www.googgun.com</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.bitarmor.com/2008/06/it-admin-bad-guy-not-sure-i-buy-it-much.html' ref='tag:blogger.com,1999:blog-4391522908329730957.post-1545767919699374951' source='http://www.blogger.com/feeds/4391522908329730957/posts/default/1545767919699374951' type='text/html'/></entry></feed>