Vendors urged to take responsibility for security

By Colin Barker, ZDNet UK
Thursday, April 24, 2008 02:47 PM

While companies may go to great lengths to ensure their IT environments are secure, technology vendors need to do more to make sure their hardware and software is up to scratch, according to security experts.

At a panel debate at Infosecurity Europe 2008 on Tuesday, security experts lined up to put some of the blame for hackers finding ways to exploit code on software makers.

Alan Paller of the SANS Institute said: "Applications have become the new target for attacks." He referred to one Oracle user he claimed had suffered 80,000 attacks on its systems.

Rhonda MacClean, chief information security officer for Barclays, explained in detail how her company routinely tests the security of most of the software it buys in from suppliers.

"Using someone else's software does not abdicate you from responsibility for the security of the code," MacClean said, and added that the constant updates and service packs made life especially difficult for in-house IT people.

"Just when you got used to the code, a new version comes along."

But despite the shortcomings of some software makers' code, IT departments are ultimately responsible for the code they use within their organizations.

"We want code that as far as security is concerned is A+," MacClean said. "But when we tested code [at Barclays] we found a lot of it was C-."

According to MacClean, the problem is relatively easy to improve. "We talk to [the suppliers] about the problem and we have got much better code as a result," she said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web