* Experts give their definition of 'policy'
endif; ?>The dust seems to have settled so it’s probably a good time to wrap up our discussion of rules, policies and a potential policy access protocol.
To refresh your memory, back in mid-August (see link below) I mentioned that Ira Horowitz, MaXware’s director of worldwide marketing, along with Senior Solution Designer Torgeir Pedersen had noted that the company’s new Virtual Policy Server would require other vendors to write to its programming interface in order to use it. We kicked around the idea of a standardized “Policy Access Protocol,” most likely XML-based, so that policy information could be exchanged between and among storage, enforcement and client policy access points.
This immediately (https://www.nwfusion.com/newsletters/dir/2004/0830id2.html) raised an issue of confusion of the term Policy Access Protocol with the existing Access Control Markup Language (XACML), which I suggested to be the basis for the new data exchange mechanism. But the bigger problem was raised by Fino Napoleone vice president of technology and services for Blockade Systems, when he questioned the very definition of “policy.”
It’s an issue that comes up periodically, but is occurring more and more as directory-based identity management vendors and security-based identity management vendors attempt to compete and cooperate in the same space. So I called on any interested party to step up and come up with a good working definition of “policy.”
Dan Beckett, a senior consult at The Burton Group was first out of the box. He pulled no punches when he said: “I believe that ‘policy’ is far too general of a term, and has historically (and erroneously) been used to denote the concept of ‘enforcement’ by software vendors. This probably all began when firewall vendors began describing ‘rules’ as ‘policies,’ and using those terms interchangeably…” The first shot across the bow had been fired, and Beckett took dead aim at the security sector as the responsible parties for misusing the term “policy.”
Jeff Davis, a director of product architecture at SafeStone weighed in and, in general, agreed with Beckett that what many call “policies” are really rules. More importantly, they are rules designed to support policies “very high-level” and “should be paper-based.” Davis adds, “Rules are then codified to support the policy.”
Azi Cohen, CEO of Eurekify, was next up and he slowed the bandwagon by reminding us that it was often easier to formulate a policy than it was to create the rules to implement it.
Consul Risk Management Chief Technologist Kris Lovejoy chimed in on the definition of policy, stating that: “A policy sets the course: defining how confidentiality, integrity and availability of information and technology assets can be achieved and maintained (example, Acceptable Use Policy).” Lovejoy didn’t directly address the use of rules, though.
In a tightly reasoned contribution to the discussion, Network World columnist and Burton Group senior analyst James Kobielus summed up by stating: “I agree with you that the fundamental construct is ‘rule,’ not ‘policy.'”
So there you have it. Most people venturing an opinion agreed that what we frequently call “policies” should really be called “rules.” I’m gratified that we mostly agree, but I’m not optimistic that we’ll change the course of history. If we all try hard to use the terms properly and we correct misuse at every opportunity, it’s possible we’ll make the discussion easier to understand. It’s more likely, though, that you’ll join me in acquiring the nickname “curmudgeon.” Fight the good fight!




