While security is a needed part of
any company there are many other things which help to keep them more secure in
their daily operations. These security measures do not include disclose of
information about the company’s security. While this information could be important
for potential clients it becomes a security risk for the company more often
than not.
While I agree with the principle of
avoiding “security through obscurity,” I would not recommend a company to give
up much of their information about their security practices. There are some
security disclosure postings which would hurt a company and therefore should
never be freely disclosed to the general population. I think that a company
could disclose some information about their practices and operational strategy to
the general public but the information would be so limited and vague that it
would not be useful for customer to know this information. Even without this
information a customer should never decide to use a password based on the
lowest settings required by the company they should always use a strong
password and determine for their self if a password’s strength is applicable
for a certain type of account.
To show that there is a proper
level of security which is in place at a company there should be some
categories of “low hanging fruit” which a company should receive a compliance
score regarding, and this score could be shared with the public after an
appropriate amount of time for the company to fix any shortcomings that they
may have. With this scoring system there would be an increase in the disclosure
for companies with higher levels of security while still giving them protection
from releasing too much information. While there are many possibilities for
disclosure for a company’s security settings full disclosure should not be
considered with how the world operates currently.
Seems reasonable to me...
ReplyDelete