{"title":"A Wish List of Security and Continuity Technologies","authors":"Harry B. DeMaio","doi":"10.1080/10658989509342483","DOIUrl":"https://doi.org/10.1080/10658989509342483","url":null,"abstract":"","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"4 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"129643979","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Groupware - Hazardous to Your Health?","authors":"Harry B. DeMaio","doi":"10.1080/10658989409342449","DOIUrl":"https://doi.org/10.1080/10658989409342449","url":null,"abstract":"","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"3 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"129649028","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Quantifying and Lowering Security Costs - Hard Dollars","authors":"Philip Carden","doi":"10.1201/1086/43301.7.4.19990101/31016.5","DOIUrl":"https://doi.org/10.1201/1086/43301.7.4.19990101/31016.5","url":null,"abstract":"Abstract Businesses today use the Internet primarily as a means of providing fast convenient access to public information. But, the potential business uses go much further. Electronic commerce, for example, significantly will lower the cost of dayto-day business transactions, and virtual private networks provide a lower-cost alternative to traditional data and even voice networks. However, these advanced uses of the Internet require a stronger security infrastructure than most companies have in place today. This means greater costs associated with security but, until recently, there was very little data even on today's cost of security. The author recently was involved in conducting primary research that addresses this issue and shares the findings and a look at tactical approaches that can start to control those costs.","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"35 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130052342","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Information Protection and Business Process Reengineering","authors":"Harry B. DeMaio","doi":"10.1080/10658989509342472","DOIUrl":"https://doi.org/10.1080/10658989509342472","url":null,"abstract":"Taylor & Francis makes every effort to ensure the accuracy of all the information (the “Content”) contained in the publications on our platform. However, Taylor & Francis, our agents, and our licensors make no representations or warranties whatsoever as to the accuracy, completeness, or suitability for any purpose of the Content. Any opinions and views expressed in this publication are the opinions and views of the authors, and are not the views of or endorsed by Taylor & Francis. The accuracy of the Content should not be relied upon and should be independently verified with primary sources of information. Taylor and Francis shall not be liable for any losses, actions, claims, proceedings, demands, costs, expenses, damages, and other liabilities whatsoever or howsoever caused arising directly or indirectly in connection with, in relation to or arising out of the use of the Content.","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"38 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122353143","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"From the Editor","authors":"D. Parker","doi":"10.1080/19393559308551322","DOIUrl":"https://doi.org/10.1080/19393559308551322","url":null,"abstract":"","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"23 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"123351924","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Possession as an Element of Information Security","authors":"D. Parker","doi":"10.1080/10658989509342496","DOIUrl":"https://doi.org/10.1080/10658989509342496","url":null,"abstract":"Taylor & Francis makes every effort to ensure the accuracy of all the information (the “Content”) contained in the publications on our platform. However, Taylor & Francis, our agents, and our licensors make no representations or warranties whatsoever as to the accuracy, completeness, or suitability for any purpose of the Content. Any opinions and views expressed in this publication are the opinions and views of the authors, and are not the views of or endorsed by Taylor & Francis. The accuracy of the Content should not be relied upon and should be independently verified with primary sources of information. Taylor and Francis shall not be liable for any losses, actions, claims, proceedings, demands, costs, expenses, damages, and other liabilities whatsoever or howsoever caused arising directly or indirectly in connection with, in relation to or arising out of the use of the Content.","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116120737","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Computers at Risk: Does Anyone Remember?","authors":"Chris McDonald","doi":"10.1080/19393559308551336","DOIUrl":"https://doi.org/10.1080/19393559308551336","url":null,"abstract":"In the fall of 1988, the Defense Advanced Research Projects Agency (DARPA) funded the Computer Science and Telecommunications Board of the National Research Council to address the security and trustworthiness of US computing and communications systems. The board formed the System Security Study Committee, consisting of 16 distinguished representatives from government, academia, and the commercial sectors. David Clark, a senior research scientist at the Laboratory for Computer Science at the Massachusetts Institute of Technology, chaired the committee. Meeting three times each in 1989 and 1990, the committee conferred with federal government researchers as well as with officials and security experts from industry. Its findings were published in early 1991 in the report Computers at Risk: Safe Computing in the Information Age. As noted in preface to the report, the committee attempted to forge a \"consensus in the face of different technical and professional perspectives.\"","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"30 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116742827","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"UNIX and Security: The Influences of History","authors":"E. Spafford","doi":"10.1080/10658989509342510","DOIUrl":"https://doi.org/10.1080/10658989509342510","url":null,"abstract":"UNIX has a reputation as an operating system that is difficult to secure. This reputation is largely unfounded. Instead, the blame lies partially with the traditional use of UNIX and partially with the poor security consciousness of its users. UNIX's reputation as a nonsecure operating system comes not from design flaws but from practice. For its first 15 years, UNIX was used primarily in academic and computer industrial environments two places where computer security has not been a priority until recently. Users in these environments often configured their systems with lax security, and even developed philosophies that viewed security as something to avoid. Because they cater to this community, (and hire from it) many UNIX vendors have been slow to incorporate stringent security mechanisms into their systems. This paper describes how the history and development of UNIX can be viewed as the source of the most serious problems. Some suggestions are made of approaches to help increase the security of your system, and of the UNIX community.","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"21 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132659301","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Controlling the Data Base Administrator","authors":"G. W. Joseph, T. Engle","doi":"10.1080/19393559308551355","DOIUrl":"https://doi.org/10.1080/19393559308551355","url":null,"abstract":"The data base administrator (DBA) function is an essential element of a properly operated data base system. Although the vast majority of DBAs maintain the highest ethical standards, it must be recognized that these individuals are commonly in a particularly powerful position with respect to the organization's information systems, possessing the ability to inflict significant harm. This article describes the typical functions of a DBA and the specific methods that a DBA could employ to manipulate an organization's data base for personal gain, for the gain of others, or for misdirected benefit to the organization itself. In addition, this article discusses a variety of internal control procedures that can be used to effectively mitigate the risk of such inappropriate activity. Finally, warning signs that may indicate an increased risk of inappropriate DBA activity are presented.","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"68 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"134124199","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Security and Controls for EDI","authors":"G. Benesko, Philip Teplitzky","doi":"10.1080/10658989409342451","DOIUrl":"https://doi.org/10.1080/10658989409342451","url":null,"abstract":"","PeriodicalId":207082,"journal":{"name":"Inf. Secur. J. A Glob. Perspect.","volume":"25 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"134309463","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}