[181198] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: OPM Data Breach - Whitehouse Petition - Help Wanted

daemon@ATHENA.MIT.EDU (Scott Weeks)
Thu Jun 18 14:15:40 2015

X-Original-To: nanog@nanog.org
Date: Thu, 18 Jun 2015 11:12:03 -0700
From: "Scott Weeks" <surfer@mauigateway.com>
To: <nanog@nanog.org>
Reply-To: surfer@mauigateway.com
Errors-To: nanog-bounces@nanog.org



--- bill@herrin.us wrote:
From: William Herrin <bill@herrin.us>

The core problem here is that the Authority To Operate (ATO) process
consumes essentially the entire activity of a USG computing project's
security staff. The non-sensical compliance requirements, which if
taken literally just about prevent you from ever connecting any
computer to any other, get in the way of architecting systems around
pragmatic and effective security.
--------------------------------------------


"non-sensical compliance"  Yeah, that.  Pure, unmitigated insanity.

scott

home help back first fref pref prev next nref lref last post