Effective security involves constantly reinforcing security mechanisms and policies by training and periodically adapting to account for new threats. Security protects and extends competitive advantage. But there are costs associated with all security procedures and these costs must be weighed against the value of the assets protected by those measures and the potential harm which could be caused by the loss of that asset. A company which wishes to advertise on the Web may be satisfied with a simple firewall to discourage electronic vandals. A large financial institute with billions of dollars at stake could justify much more elaborate security measures, possibly including public key encryption, dedicated private networks, and regular security audits. For applications like air traffic control and military and intelligence systems, the risk of connecting these systems to the internet may outweigh the benefits of being on the internet.
The cost of implementing security mechanisms is a very crucial factor too. If a new technology makes it easier or cheaper to obtain the same level of security as an existing system, it would be very attractive. On the other hand, if it increases the security with a corresponding increase in cost, the organization must weigh the cost against the risks being averted. Figure 14.1 shows the tradeoff between security and cost.
When calculating security costs, usability is an important factor. If security mechanisms are too time-consuming or difficult to use, they can decrease the productivity. Users who find the policies difficult to follow may ignore the policies or implement them haphazardly.
Java is able to provide transparent security mechanisms, which do not require any knowledge or action on the part of the end user. This is possible because Java's security model is meant to protect the end-user from hostile applets from untrusted sources.
Copyright © 1996 Virginia Polytechnic Institute & State University
All Rights Reserved
Vijay Sureshkumar
<vijay@csgrad.cs.vt.edugt;
Last modified: Sun Oct 20 21:52:09 1996