Labeling-in Security

Fred B. Schneider · IEEE Security & Privacy · 2009

Using exams to create labels for our workforce might sound like a way to get more trustworthy systems, but it's not. If it walks like a duck, quacks like a duck, and looks like a duck, then there's good reason to believe that it's a duck. But you don't get a duck just by calling something a duck, and you don't get trustworthy systems simply by introducing a labeling scheme for system-builders. You can't label-in security. To have the desired effect, a credential must bestow obligations and responsibilities on practitioners.

Read the paper · More papers on PaperTik