|
|
|
|
|
by solotronics
2564 days ago
|
|
I have started thinking this is a major systemic weakness the US has vs China. Companies in America operate as individual entities more or less vs the top down model in China. Every company I have worked with in China had a group of government agents it just seems to be standard operating procedure there. Maybe they weren't around for day to day operations but they were definitely around whenever Americans were there. It's apparent they have vast cyber and intel efforts intertwined with the major corporations. Contrast this to our model, I don't even know how to alert the US government if I see something suspicious related to cyber security. |
|
If China wants a model, the TCSEC is a decent start at one. It was made for military requirements, though. Like MLS. The next approach should focus on commercial needs. Also, both TCSEC and Common Criteria were paper heavy with long evaluations after product development was done. The next should focus on actual code with reviewers getting into the process early on, reviewing deliverable by deliverable, so they have better insight into what's going on with faster time to market. Lots of room for improvement over the current model.
TCSEC
https://en.wikipedia.org/wiki/Trusted_Computer_System_Evalua...
Example of what industry was doing under TCSEC
https://csrc.nist.gov/csrc/media/publications/conference-pap...
Modern example from that lineage:
https://os.inf.tu-dresden.de/papers_ps/nizza.pdf