Difference between revisions of "Responsibility"
(→Context) |
(→References) |
||
| Line 15: | Line 15: | ||
# The installer | # The installer | ||
# The Owner | # The Owner | ||
| + | |||
| + | ==Authorization== | ||
| + | |||
| + | ==Deployed Systems== | ||
| + | ===Updating software=== | ||
| + | A debate has been raging (in 2023) about whether the owner should be responsible for updates. An argument has been made the the manufacturer should bear full responsibility for failures and would then be incentivized to make the software better. For an extreme example see [[Code of Hammurabi]]. But if there were unlimited liability by the manufacture there would very few of them in business.<ref>Steve Lipner +1, ''Updates, Threats, and Risk Management'' (2023-05) '''CACM 66''' No. 5 p. 21-23</ref> | ||
==References== | ==References== | ||
[[Category: Glossary]] | [[Category: Glossary]] | ||
Revision as of 16:04, 26 May 2023
Contents
Full Title or Meme
The state or fact of being accountable or to blame for something.
The opportunity or ability to act independently and make decisions without authorization.
Context
In Identity and Access Management Responsibility is a topic of major concern. Who, exactly, should be responsible for acts taken to identify the person who has Authorization to act?
- Issuer of an Identity Credential
- Holder of an Identity Credential
- Verifier of an Identity Credential
In computer software and hardware deployment who should be responsible for failures of the the deployment?
- The manufacturer
- The installer
- The Owner
Authorization
Deployed Systems
Updating software
A debate has been raging (in 2023) about whether the owner should be responsible for updates. An argument has been made the the manufacturer should bear full responsibility for failures and would then be incentivized to make the software better. For an extreme example see Code of Hammurabi. But if there were unlimited liability by the manufacture there would very few of them in business.[1]
References
- ↑ Steve Lipner +1, Updates, Threats, and Risk Management (2023-05) CACM 66 No. 5 p. 21-23