Educause Security Discussion mailing list archives

Re: Are users right in rejecting security advice?


From: Eric Case <ecase () EMAIL ARIZONA EDU>
Date: Wed, 17 Mar 2010 11:51:40 -0700

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Michael Sinatra
Sent: Wednesday, March 17, 2010 11:25 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Are users right in rejecting security advice?


I agree completely that it's more useful to communicate risks than to
have rigid policies.  That allows the users to put in compensating
controls that fit their needs.

Is it then ok if the user accepts more risk than the institution is willing
to accept?
-Eric



Eric Case, CISSP
eric (at) ericcase (dot) com
http://www.linkedin.com/in/ericcase

Current thread: