Vendors urged to take responsibility for security

By Colin Barker, ZDNet UK
Thursday, April 24, 2008 02:47 PM

While companies may go to great lengths to ensure their IT environments are secure, technology vendors need to do more to make sure their hardware and software is up to scratch, according to security experts.

At a panel debate at Infosecurity Europe 2008 on Tuesday, security experts lined up to put some of the blame for hackers finding ways to exploit code on software makers.

Alan Paller of the SANS Institute said: "Applications have become the new target for attacks." He referred to one Oracle user he claimed had suffered 80,000 attacks on its systems.

Rhonda MacClean, chief information security officer for Barclays, explained in detail how her company routinely tests the security of most of the software it buys in from suppliers.

"Using someone else's software does not abdicate you from responsibility for the security of the code," MacClean said, and added that the constant updates and service packs made life especially difficult for in-house IT people.

"Just when you got used to the code, a new version comes along."

But despite the shortcomings of some software makers' code, IT departments are ultimately responsible for the code they use within their organizations.

"We want code that as far as security is concerned is A+," MacClean said. "But when we tested code [at Barclays] we found a lot of it was C-."

According to MacClean, the problem is relatively easy to improve. "We talk to [the suppliers] about the problem and we have got much better code as a result," she said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Mainsoft: Opening options for Java, .NET developers

Java

Mainsoft provides tools for running .NET code on the Java platform.


Read more »


Tags

  1. against
  2. antivirus
  3. asian
  4. attacks
  5. blame
  6. by
  7. critical
  8. cyber
  9. data
  10. flaw
  11. flaws
  12. google
  13. govt
  14. hit
  15. hp
  16. malware
  17. microsoft
  18. online
  19. over
  20. security
  21. software
  22. symantec
  23. threats
  24. uk
  25. under
  26. update
  27. updates
  28. us
  29. warns
  30. web
 
Increase performance with eco-technology innovations
Simplify your infrastructure and unify management, while lowering power and cooling costs of your datacenter.
» Maximum flexibility with powerful blade technolgy
» Bring new services and applications online faster
» Lower energy use and cost
Oracle SOA Business Software Centre
Many companies are recognizing the need to adopt standards in their efforts to build service-oriented applications.
Secure the "Next-Gen SOA Infrastructure" & "Bringing SOA Value Patterns to Life" whitepapers here

» Visit the Power Center

Up close and personal with a merger

Blog thumbnail

What can you get for 13.9 billion buckaroos? For Hewlett-Packard, US$13.9 billion would allow you to buy your way into becoming the second biggest IT services company in the industry...... by Eileen Yu

Read more »