Monday 14 September 2009

Black list versus white list

As long as I have been active in the IT-industry the methodology for internal security has been blacklisting. You can reach almost everything but we will close down access to certain resources. That was probably OK "in the old days""when there where an limited amount of information accessible. I therefore think white-listing is much easier to use: block everything and give access only to information that is needed for the given task. Much easier, much more secure...and probably more cost-effective.