Computer security -- Fiction; Didactic fiction; Privacy, Right of -- Fiction; Records -- Access control -- Fiction
"In my opinion it borders on insanity. It means that for the
price of a bit of electronic equipment, anyone can tap into the
details of the financial dealings of banks, the government and
every citizen in this country."
Senator Deere visibly gulped. "Thank you, please continue."
"In 1984, President Reagan signed National Security Decision
Directive 145. NSDD-145 established that defense contractors and
other organizations that handle sensitive or classified informa-
tion must adhere to certain security and privacy guidelines. A
number of advisory groups were established, and to a minimal
extent, the recommendations have been implemented, but I must
emphasize, to a minimal extent."
"Can you be a little more specific, Mr. Hammacher?" Asked Senator
Deere.
"No ma'am, I can't. A great deal of these efforts are classified
and by divulging who is not currently in compliance would be a
security violation in itself. It would be fair to say, though,
that the majority of those organizations targeted for additional
security measures fall far short of the government's intentions
and desires. I am sorry I cannot be more specific."
"I understand completely. Once again," Nancy said to Hammacher,
"I am sorry to interrupt."
"Not at all, Senator." Hammacher sipped from his water glass.
"As you can see, the interest in security was primarily from the
government, and more specifically the defense community. In
1981, the Department of Defense chartered the DoD Computer Secu-
rity Center which has since become the National Computer Security
Center operating under the auspices of the National Security
Agency. In 1983 they published a series of guidelines to be used
in the creation or evaluation of computer security. Officially
titled the Trusted Computer Security Evaluation Criteria, it is
popularly known as the Orange Book. It has had some minor
updates since then, but by and large it is an outdated document
designed for older computer architectures.
"The point to be made here is that while the government had an
ostensible interest and concern about the security of computers,
especially those under their control, there was virtually no
overt significance placed upon the security of private industry's
computers. Worse yet, it was not until 1987 that any proposed
criteria were developed for networked computers. So, as the
world tied itself together with millions of computers and net-
works, the Government was not concerned enough to address the
issue. Even today, there are no secure network criteria that are
universally accepted."
Public-domain text, read in full here on John Shaqi.
Reviews
Reviews
No reviews yet
Be the first to share your thoughts on this work.
Elsewhere in the archive
Join the Discussion
Join the discussion
Sign in to leave a comment or review.
Sign InorCreate an account