|
Does Verizon's Voyager stack up to the iPhone? |
|
|
5 IT skills that won't boost your salary
[1,407]
Women 4 times more likely than men to cough up personal info
[589]
Japan's 10 funniest tech-related commercials [Videos]
[407]
Throwing away a promo CD is "unauthorized distribution"?
[1,265]
Adults too quick to dismiss educational video games
[682]
Attack of the iPhone clones [Slideshow]
[578]
10 things IT needs to know about AJAX
[1,258]
This Year's 25 Geekiest 25th Anniversaries [Slideshow]
[409]
|
|
What does it solve?
While this is a very good synopsis regarding the current state of thinking by groups such as Jericho and others in the security industry, I wonder why there is not a single mention of the concept of information-centric security?
This is surprising since this is one concept that would seem to be integral to the whole concept of de-perimeterization and the goals of Jericho. What is there in the endpoint approach that answers the basic necessary question of "who is accessing what data and what are they are allowed to do with it" ?
At most, the authenticated endpoint device becomes only the most basic of proxies for authorized access to the network. On the other hand, a granular access and audit control system that operates on a whitelist basis at the data level and incorporates the clearly understood trust level boundaries that the author alludes to in his article, makes the endpoint device issue a non-issue.