Security policy audits: why and how

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Narayanan, Arvind, Lee, Kevin
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909145406373888
author Narayanan, Arvind
Lee, Kevin
author_facet Narayanan, Arvind
Lee, Kevin
contents Information security isn't just about software and hardware -- it's at least as much about policies and processes. But the research community overwhelmingly focuses on the former over the latter, while gaping policy and process problems persist. In this experience paper, we describe a series of security policy audits that we conducted, exposing policy flaws affecting billions of users that can be -- and often are -- exploited by low-tech attackers who don't need to use any tools or exploit software vulnerabilities. The solutions, in turn, need to be policy-based. We advocate for the study of policies and processes, point out its intellectual and practical challenges, lay out our theory of change, and present a research agenda.
format Preprint
id arxiv_https___arxiv_org_abs_2207_11306
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Security policy audits: why and how
Narayanan, Arvind
Lee, Kevin
Cryptography and Security
Computers and Society
Information security isn't just about software and hardware -- it's at least as much about policies and processes. But the research community overwhelmingly focuses on the former over the latter, while gaping policy and process problems persist. In this experience paper, we describe a series of security policy audits that we conducted, exposing policy flaws affecting billions of users that can be -- and often are -- exploited by low-tech attackers who don't need to use any tools or exploit software vulnerabilities. The solutions, in turn, need to be policy-based. We advocate for the study of policies and processes, point out its intellectual and practical challenges, lay out our theory of change, and present a research agenda.
title Security policy audits: why and how
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2207.11306