
Ravi Sandhu, executive director for the Institute for Cyber Security, was interviewed in an article by SC Magazine yesterday on risk management and security assurance. From the article:
"Just deploying products that have achieved a
certain level of security doesn't mean your overall system is going to
be secure. Let's say you buy a product that does encryption. Encryption
can be very strong and resistant to cryptographic attacks, but if you
don't manage the keys, your overall system can be compromised...At
the end of the day, security is about risk management and risk
mitigation at the system level.
Additionally, Ravi was interviewed today by the San Antonio Business Journal on extending the reach of cyber security. From the article:
“Ultimately, (cyber security) will have to develop as a separate
field,” Sandhu says. “Right now it is embedded within the computer
science field, but it needs to be treated as a discipline by itself.” Sandhu also says most computer science graduates today are coming out
with very superficial knowledge of cyber security. Because the field of
cyber security is changing and evolving at such a rapid pace, it is not
enough for universities to be teaching just the old ideas about cyber
security.
For more on ICS's work on risk management, cyber security and assurance, visit the
ICS site.
Erhan J. Kartaltepe,
erhan.kartaltepe-at-utsa.edu