Is whitelisting the best solution?

A recent report from the Pacific Northwest National Laboratory and McAfee has concluded that the best solution for securing industrial control systems in the critical public infrastructure is whitelisting – the practice of excluded all but what is explicitly allowed (in contrast to blacklisting, which allows all that is not explicitly excluded). Your company’s data assets and infrastructure might not be as important to the country as the ones they’re talking about protecting, but chances are they are critically important to you. Should you take a tip from this report and consider the same solution?

