We were given a group activity that tested our knowledge in security. The one that was given to us was a grocery store with only two guards as their security, no CCTV or whatsoever, and they rely with the "honesty system" which lead them to lose merchandise that cost 10K pesos a month. That loss has been happening for 6 months.
My group and I thought about solutions that cost zero cash so every recommendations are more on adjusting how the employees should work. I thought about the whistleblowing system where person raises concern about a wrong doing when he/she sees one.
During our presentation, our professor said it was creative of us to put it as our solution, the whistleblowing system. He even said that companies would be happy to us since our solutions are cost-free. All in all the presentation went well.
In the last lesson, I've come to realize that not all top privileged users are allowed to access all the resources. Mandatory Access Control (MAC) having labels of Public-->Confidential-->Secret-->Top Secret resources. The Top Secret, which is the highest, may not be given an access to Secret because errors/mistakes can happen. Top secret data could be mistakenly sent to the Secret that's why it is risky when a user can access everything.
My group and I thought about solutions that cost zero cash so every recommendations are more on adjusting how the employees should work. I thought about the whistleblowing system where person raises concern about a wrong doing when he/she sees one.
During our presentation, our professor said it was creative of us to put it as our solution, the whistleblowing system. He even said that companies would be happy to us since our solutions are cost-free. All in all the presentation went well.
In the last lesson, I've come to realize that not all top privileged users are allowed to access all the resources. Mandatory Access Control (MAC) having labels of Public-->Confidential-->Secret-->Top Secret resources. The Top Secret, which is the highest, may not be given an access to Secret because errors/mistakes can happen. Top secret data could be mistakenly sent to the Secret that's why it is risky when a user can access everything.
Yes your solution is very management-oriented and creative! hehe
ReplyDelete