The various aspects to the security problem are:
- Legal, social and ethical aspects (for example, does the person making the request, say for withdrawing money from a bank, has legal rights for making the requested transaction?)
- Physical controls (for example, is the computer or terminal room always locked or otherwise guarded.)
- Policy Questions (for example, how does the enterprise owning the system decide who should be allowed access and to what?)
- Operational problems (for example, is a password scheme is used, how are the passwords themselves kept secret? how often are they changed?)
- Hardware controls (for example, does the processing unit provide any security features, such as the storage protection keys or a privileged operation mode?)
- Operating system security (for example, does the underlying operating system erase the contents of storage and data files when they are finished with?)
0 comments:
Post a Comment