Welcome to MSDN Blogs Sign in | Join | Help

Computer Science Teacher - Thoughts and Information from Alfred Thompson

Alfred Thompson's blog about teaching computer science at the K-12 level. Alfred was a high school computer science teacher for 8 years. He has also taught grades K-8 as a computer specialist. He has written several textbooks and project books for teaching Visual Basic in high school and middle school. Alfred is the K-12 Computer Science Academic Relations Manager for Microsoft and is trying to be the Microsoft Education Blogger.

Syndication

News


Featured in Education.AllTop.com



TwitterCounter for @alfredtwo




Talking about Defense in Depth

Last week I was down at Pace University in New York City where I gave the opening keynote talk for a high school computer forensics competition. I had a very attentive audience for my talk but I also I really enjoyed seeing/hearing the presentations the students did for the competition. There was clearly a lot of work and a lot of learning going on. One of the things I talked about in my talk, which was generally about defensive actions to protect software in general and operating systems in particular, was Defense in Depth. I only spent a short time on it but it was clear to me that I could have spent a lot more time on it. As regular readers know I believe that students in computer science should start learning about security early.

Just by coincidence, this week, I received the regular security newsletter that Microsoft sends out and there was a reference to an article by Kai Axford, a Senior Security Strategist with the Microsoft Trustworthy Computing Group, on this very topic. In this article Kai talks about Seven Layers of defense in depth:

  • Layer 1 Policies, Procedures, and Awareness (All Bark and No Bite)
  • Layer 2: Physical Security (Gates, Guards, and Guns)
  • Layer 3: Perimeter Security (Living on the Edge)
  • Layer 4: Network Security (Protecting Your House)
  • Layer 5: Host Security (Save the Box, Save the Network)
  • Layer 6: Application Security (If You Build It…Securely, They Won't Come)
  • Layer 7: Data Security (If Your Terabyte Falls in the Middle of the Active Directory Forest…)

It’s not a long article but there is a lot of good information and a good start to a serious discussion about software as part of a complete system and what it means to keep things safe. And if you want more, you can find Kai’s highly rated on-demand videos here.

Published Friday, June 13, 2008 11:13 AM by Alfred Thompson

Filed under: ,

Comments

No Comments

New Comments to this post are disabled
Page view tracker