Forum Discussion
daveu8282_20327
Feb 15, 2011Nimbostratus
Policy creation: who's in the driver's seat?
We have ASM 10.1.0 in-house. We've not yet gotten around to putting it into use but I've lately been asked to setting up policies for some of our applications. I've taken a look at the Getting Started...
hooleylist
Feb 17, 2011Cirrostratus
Your situation is pretty similar to the customers I was working with on ASM. I don't like the idea of app owners exclusively maintaining the policy. Management generally already places too much emphasis on functionality and new features over security. If there is no one outside them and the app owners to dictate security policy, you end up with very open, insecure implementations.
If you feel like publishing anonymized versions of any of your documentation or processes, I'm sure other ASM admins would appreciate it. I know a lot might be specific to your company, but I imagine a decent amount could go towards helping others establish best practices.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects