You are here: silicon.com > Software > Security Strategy

Security Strategy

Security - vendors must take some responsibility

Apps new target for attacks

Tags: vendor, security

By Colin Barker

Published: 23 April 2008 15:52 GMT

While companies may go to great lengths to ensure their IT environments are secure, technology vendors need to do more to make sure their hardware and software is up to scratch, according to security experts.

At a panel debate at Infosecurity Europe 2008, security experts lined up to put some of the blame for hackers finding ways to exploit code on software makers. Alan Paller of the SANS Institute said: "Applications have become the new target for attacks," and referred to one Oracle user he claimed had suffered 80,000 attacks on its systems.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

Rhonda MacClean, chief information security officer for Barclays, explained in detail how her company routinely tests the security of most of the software it buys in from suppliers.

MacClean said: "Using someone else's software does not abdicate you from responsibility for the security of the code." She added that the constant updates and service packs made life especially difficult for in-house IT people. "Just when you got used to the code, a new version comes along."

But despite the shortcomings of some software makers' code, IT departments are ultimately responsible for the code they use within their organisations.

MacClean said: "We want code that, as far as security is concerned, is A+. But when we tested code [at Barclays] we found a lot of it was C-."

According to MacClean, the problem is relatively easy to improve. She said: "We talk to [the suppliers] about the problem and we have got much better code as a result."

Original article: Vendors urged to take responsibility for security from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Data leaks highlight need for content security Quocirca's Straight Talking: What's the best way to do it?

Naked CIO Naked CIO: Has tech made us dumber? Or the business anyway...


  • Jobs
Business Analyst Market Data, Banking (Reuters / Bloomberg)

The Global Market Data team in this bank is built up of the leading market data experts in the industry. Candidates absolutely must be EXPERTS in the ...

Network and Systems Administrator

Symantec Backup Exec)• Experience with antivirus software deployment/management • Liaison with all external contractors, suppliers and ...

Training Manager (SC Cleared)

Identify learning needs with line managers and subject matter experts - Technical, induction, professional, process, legal etc. Guide and coach ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: