Monday, September 10, 2012

Corporate Practices of Disclosure?


While security is a needed part of any company there are many other things which help to keep them more secure in their daily operations. These security measures do not include disclose of information about the company’s security. While this information could be important for potential clients it becomes a security risk for the company more often than not.
While I agree with the principle of avoiding “security through obscurity,” I would not recommend a company to give up much of their information about their security practices. There are some security disclosure postings which would hurt a company and therefore should never be freely disclosed to the general population. I think that a company could disclose some information about their practices and operational strategy to the general public but the information would be so limited and vague that it would not be useful for customer to know this information. Even without this information a customer should never decide to use a password based on the lowest settings required by the company they should always use a strong password and determine for their self if a password’s strength is applicable for a certain type of account.
To show that there is a proper level of security which is in place at a company there should be some categories of “low hanging fruit” which a company should receive a compliance score regarding, and this score could be shared with the public after an appropriate amount of time for the company to fix any shortcomings that they may have. With this scoring system there would be an increase in the disclosure for companies with higher levels of security while still giving them protection from releasing too much information. While there are many possibilities for disclosure for a company’s security settings full disclosure should not be considered with how the world operates currently. 

1 comment: