<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Miscellaneous Ramblings &#187; process</title>
	<atom:link href="http://onastick.wordpress.com/tag/process/feed/" rel="self" type="application/rss+xml" />
	<link>http://onastick.wordpress.com</link>
	<description>Hockey, Disc golf, devops and other assorting miscellany.</description>
	<lastBuildDate>Wed, 18 Jan 2012 17:39:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='onastick.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Miscellaneous Ramblings &#187; process</title>
		<link>http://onastick.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://onastick.wordpress.com/osd.xml" title="Miscellaneous Ramblings" />
	<atom:link rel='hub' href='http://onastick.wordpress.com/?pushpress=hub'/>
		<item>
		<title>When security takes a backseat to process&#8230;</title>
		<link>http://onastick.wordpress.com/2009/02/16/when-security-takes-a-backseat-to-process/</link>
		<comments>http://onastick.wordpress.com/2009/02/16/when-security-takes-a-backseat-to-process/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 15:54:16 +0000</pubDate>
		<dc:creator>stick</dc:creator>
				<category><![CDATA[Sysadminery]]></category>
		<category><![CDATA[itil]]></category>
		<category><![CDATA[process]]></category>

		<guid isPermaLink="false">http://www.miscellaneous.net/?p=198</guid>
		<description><![CDATA[We are currently going through an ITIL implementation.  It&#8217;s had it&#8217;s ups and downs and philosophically I don&#8217;t really believe in it (certainly not in our implementation), but it&#8217;s had a few successes and a few failures.  Without droning too much about it, to make any &#8216;production&#8217; change you have to file an RFC that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=onastick.wordpress.com&amp;blog=19419720&amp;post=198&amp;subd=onastick&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We are currently going through an ITIL implementation.  It&#8217;s had it&#8217;s ups and downs and philosophically I don&#8217;t really believe in it (certainly not in our implementation), but it&#8217;s had a few successes and a few failures.  Without droning too much about it, to make any &#8216;production&#8217; change you have to file an RFC that gets reviewed by a management team.  There is a relatively recent <a href="http://isc.sans.org/diary.html?storyid=5713" target="_blank">DNS attack</a> that involves using root zone recursion to DOS a target server.  We&#8217;re vulnerable to being used in this manner.  It really doesn&#8217;t affect us much  as that our servers handle the requests fine, but we&#8217;re assisting in a DDOS and that&#8217;s not good.  For us the fix is pretty straight forward, because of some historical decisions we have to allow recursion for certain ips, so I need to segment things off into a tighter view and eliminate recursion there.  This is a  pretty straight forward change and one that I would do without a second thought (after testing).  Due to our current climate of process I have to file an RFC, which is fine, I&#8217;m not real happy about it but I&#8217;ll live.</p>
<p>However my RFC was denied not because of any technical reason, not because of any concern over the technology, the implementation, or the timing.  It was denied because I didn&#8217;t put the correct information into the details page and because my dates were wrong.  I&#8217;m all for doing process right (when it makes sense), but does it make sense to derail a security fix for 4 days because the form was incorrect?  Especially when there exists a forum in which you can be asked to clarify anything regarding your RFC.</p>
<p>Now when security takes a backseat to process, your organization has truly begun the decent to failure.  This may indeed be the straw&#8230;</p>
<br />Posted in Sysadminery Tagged: itil, process <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/onastick.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/onastick.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/onastick.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/onastick.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/onastick.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/onastick.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/onastick.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/onastick.wordpress.com/198/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=onastick.wordpress.com&amp;blog=19419720&amp;post=198&amp;subd=onastick&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://onastick.wordpress.com/2009/02/16/when-security-takes-a-backseat-to-process/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/10dcfb54c464136b8be684b80ddd3515?s=96&#38;d=monsterid&#38;r=G" medium="image">
			<media:title type="html">stickm13</media:title>
		</media:content>
	</item>
	</channel>
</rss>
