Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
Computerworld Publication PageNetworkWorld Publication PageCIO Canada Publication PageITJobUniverse.ca
- The Information, Communication and Technology (ICT) Job Board
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network"Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network" read more
From fear to value: CIO strategies for propelling business through the economic crisisFrom fear to value: CIO strategies for propelling business through the economic crisis read more
Reaping the rewards of your service-oriented architecture infrastructureReaping the rewards of your service-oriented architecture infrastructure read more
Yuk it Up
Featured White Paper
Ensuring that IT security is delivering true value to the organization requires approaching security through a business lens, with the ability to span operational silos and IT domains to secure your critical business processes across the organization. Read on to learn how to help mitigate enterprise security risks by leveraging IBM solutions to drive business innovation and success, while reducing complexity and costs along the way.
IT World Canada Blogs
Keep up with breaking news on worms, trojans, spam and other threats to your corporate network and hear about the best practices in risk management from some of Canada's leading experts.
Salary Calculator 2009
Check out Computerworld Canada's 2009 Salary Calculator. Access up-to-date information from our 2009 IT Salary Survey, including salaries, cash bonuses, and percentage increases over 2008.
Featured Spotlight
Keep up on who's hiring, who's downsizing and how the government is helping. News, job opportunities, recruiters and employment lawyers are all available.
Sign-Up for
Security
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Digg it Twitter

Why 'Black Hats' are winning app security war

The proliferation of non-technical CIOs is making it harder for IT to communicate the security risks says James McGovern of the Open Web Application Security Project (OWASP)

I wanted very much to write a column about how we've reached a turning point regarding application security.

It wasn't that I thought one particular cataclysmic event has changed our course for the better. Rather, it was an accumulation of smaller observations and developments:

-- Writers and bloggers like Jeremiah Grossman, Hugh Thompson,Gary McGraw (and many others) have done great work shedding light on the topic.

-- OWASP, the has established chapters around the world, and its Top Ten Vulnerability list is ever more widely disseminated.

-- (ISC)2 recently set forth a new certification covering application lifecycle security issues.

-- Both source-code analysis tools and application vulnerability scanners and services can help find flaws on either end of development and deployment. These technologies are maturing quickly.

-- And if there is a big one, it would be the application security requirements in version 6.6 of the PCI Data Security Standard, which went into effect this past June and essentially calls for you to use the two approaches mentioned in the preceding paragraph (if not both).

That's a good bit of app sec activity. Taken together, I thought, maybe it constitutes a quorum of some sort?

Alas, as I tried to kindle the flames of a warm and fuzzy analysis of these signs of progress, James McGovern was standing by with a bucket of cold water. McGovern is leader of the Hartford chapter of OWASP. His simple response to my hypothesis: "I think the black hats are winning."

McGovern gives three reasons:

One, companies tend to work toward consensus, which takes time. Even if an application security vulnerability becomes visible to attackers and defenders at the same time, he argues, the attackers are much quicker on the draw while the defenders go through the process of discussion and prioritization;

Two, he says outsourced application development creates some obstacles; offshore shops in particular are governed by the rule of margins, so they are discouraged from adding security steps (and therefore time, and therefore cost) to the development process;

And reason three is a bit of a kick in the seat of the pants: McGovern says that technical security is "a hard thing to participate in for non-technical people," and that the proliferation of CIOs with non-technical backgrounds has made it harder to communicate technical risk.

Can't wait to hear from CIOs on that one. Actually, I'd argue that reason three is really a problem with the communication skills of technical security people; the world isn't going to grind to a halt so everyone can learn the ins and outs of SQL injection and cross-site request forgery, so the security community is going to have to keep working on nontechnical analogies and other ways of explaining problems.

But at any rate, perhaps McGovern is right, and we haven't hit an inflection point. Yet. So what's it going to take?

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Events

Book Reviews

White Papers
Improving business through smart energy and environment policy
Businesses and public entities today face increasing pressure to develop policies that are both good for the planet and good for business. A framework developed by IBM offers businesses and other organizations a comprehensive approach to energy and environmental issues. The framework helps identify and prioritize environmental efforts by breaking down problems and opportunities into seven distinct business areas, which can then be segmented into manageable projects.