- Case Number: a20100223.1
- Status: closed
- Claimants: Michael Tänzer
- Respondents: Dominik George
Case Manager: MartinGummi
Arbitrator: UlrichSchroeter
- Date of arbitration start: 2010-03-02
- Date of ruling: 2010-06-24
- Case closed: 2010-06-25
- Complaint: ABC over Dominik George
- Relief: TBD
Before: Arbitrator UlrichSchroeter (A), Respondent: Dominik George (R), Claimant: Michael Tänzer (C), Case: a20100223.1
History Log
- 2010-02-23 (issus.c.o) case [s20100223.258]
2010-02-23 (UlrichSchroeter): added to wiki, request for CM / A
- 2010-02-23 (A): I'll take care about this case
- 2010-02-24 (A): started init mailing to (C), (R)
- 2010-02-24 (A): request to support about (R) for a list of assurances received
- 2010-02-24 (C): accepts CCA / DRP under this arbitration
- 2010-02-25 (A): rcvd from Support list of assurances rcvd from (R)
- 2010-02-25 (R): sent CV, reference contacts list, accepts CCA / DRP under this arbitration
- 2010-03-02 (Iang): accepts doing the interviewer in this ABC, scheduled for Thu 4th March
- 2010-03-02 (CM): takes care about this case
- 2010-03-02 (A): forwarded all msgs to (CM)
2010-03-04 (A): interview with (R) and Interviewer Iang happens at CeBIT 2010 about 13:00-13:40 local time. (R) and Interviewer accepts a recording for later transfer to Interview transcript and then delete the recording
- 2010-05-25 (Iang): wrotes down the interview transript from original recording.
- 2010-05-25 (A): checked interview transcript against original recording.
- 2010-05-25 (A): sending interview transcript to (CM),(R),(Iang)
- 2010-05-30 (R): accepts interview transcript
Discovery
Ruling
(R) applies for role of Support Engineer under Security Policy. Despite the fact that he is very young, he makes a plausible case that he is reliable enough to gain access to CAcert systems and data, as part of the Support Engineer work.
(R) does not have the experience with all the rules and procedures and the structure of a big organisation, but he gained enough experience with related work in a university, and he was convinced enough to read SP/SM and could follow it.
(R) will move into an existing team, so he will have contact with people he can ask if something unforeseen happens. (R) convinced us in the interview that he would first ask around, before breaking a rule.
On the other side, he had not realized that the counterpart to Support Engineers handling of unforseen situations is the Arbitration system (in the interview, Board was named as such) despite the fact he is familiar with the arbitration system, as he is claimant and also respondent in some cases.
Hence my recommendation is for team members to support (R) in his first phase in the proposed area. My recommendation for the t/l is to discuss some cases with him, to get him well trained to do his job.
Investigation of potential weaknesses in social engineering revealed that (R) has some familiarity with this topic. Within the interview Dominik also received a first training about this topic.
To the interviewer: Please delete all documents (CV, Reference list, interview recording) regarding this case from your system. Please confirm the removal with your CARS statement. The referenced documents will be held by CM/A of this case only.
Frankfurt/Main, June 24th, 2010
Execution
- 2010-06-24 (A): sent ruling notification to: (C), (R), Interviewer, (CM), cacert-arbitration, cacert-board, cacert-se mailing lists
- 2010-06-25 (IanG): As Interviewer of (R), and Transcript preparer, I had copies of relevant files. I have wiped the ZIP, the WAV, the CV, the Refs and the transcripts using a variation of this: dd if=/dev/random of=a20100223{file} bs=1m count=1 conv=notrunc / Then removed them. The partition is encrypted as well. No backups.
- 2010-06-25 (A): case closed
Similiar Cases