Yousif: Too early to tell. We still need to figure that
out, but we’ll likely need something because there
will always be this trust split between service providers
and customers.
Pappe: Let me challenge you. In principle, you’re
right. Why should an off-premise service be different
from an on-premise service if the same rules, processes,
and policies are applied? Often you don’t know the
off-premise rules and policies, as well as you know your
own policies. Let’s take the example of the famous malicious
insider. On premise, hopefully you don’t have
shared privileged IDs, so if there’s a malicious insider,
you know who it is. Does your off-premise provider
follow the same rule set? If not, the probability that
they’ll catch a malicious insider is much lower.
Yousif: Too early to tell. We still need to figure thatout, but we’ll likely need something because therewill always be this trust split between service providersand customers.Pappe: Let me challenge you. In principle, you’reright. Why should an off-premise service be differentfrom an on-premise service if the same rules, processes,and policies are applied? Often you don’t know theoff-premise rules and policies, as well as you know yourown policies. Let’s take the example of the famous maliciousinsider. On premise, hopefully you don’t haveshared privileged IDs, so if there’s a malicious insider,you know who it is. Does your off-premise providerfollow the same rule set? If not, the probability thatthey’ll catch a malicious insider is much lower.
การแปล กรุณารอสักครู่..
