Cyber-archaeology
- Gary Hinson
- Jul 11
- 1 min read
Recently, someone kindly pointed me at NBSIR 76-1041 “Security Analysis and Enhancements of Computer Operating Systems”, a fifty-year old standard from the US Department of Commerce, National Bureau of Standards (which became NIST in 1988). It was produced by the Research In Secured Operating Systems project at Lawrence Livermore Laboratory, home of the US nuclear weapons program since 1952. Parsing the glossary section revealed several alternative definitions for terms alread in the hyperglossary, plus a handful of additional terms and definitions to add.
NBSIR 76-1041 cites FIPS PUB 31 "Guidelines for Automatic Data Processing, Physical Security and Risk Management", a remarkably comprehensive standard on computer security for its day (1974) ... and still relevant today. Take a look at the contents:


Largely absent from the standard are today's cybersecurity controls for data networks. The ARPANET project had been running for 8 years in 1974, connecting university researchers with a shared interest in developing the networking technologies and protocols. The main threats were technological, accidental and benevolent rather than deliberate, malicious humans - well, as far as we know anyway. Despite the obvious threat from foreign spooks desperate to access information on top secret US nuclear weapons programs, the tools and techniques to detect and mitigate malicious network activities were primitive back then, and may themselves have been secret.

Comments