Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Green IT Playbook
Featured IT Quiz
IT Quiz: IT World Canada and IDC Canada want to know how your Green IT strategy is shaping up. Take this quiz to see how your company stacks up against other IT World Canada readers.
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.
Cybersecurity czar gets tough on responsibility
Page 1 of 1

Cybersecurity czar gets tough on responsibility

President Bush's chief cybersecurity adviser yesterday expanded the administration's concept of corporate responsibility, warning the IT industry that it is no longer acceptable to sell glitch-riddled software, and urged users to stop buying software that they know isn't secure.

"Every day in this country there are companies suffering from damages and losses" that are the result of poorly engineered software, said Richard Clarke, chairman of the President's Critical Infrastructure Protection Board. "The quality control obviously isn't there," he said, speaking at the annual Black Hat computer security conference.

Clarke's comments were met with thunderous applause from a crowd of more than 1,500 hackers and IT security experts attending this year's convention, the largest in its six-year history. As the country reels from a series of corporate corruption cases, Clarke called for the beginning of a new dialogue in the IT sector focused on corporate responsibility and transparency with respect to IT security.

Problems with software quality and security go beyond the failure of systems administrators to routinely update their systems with new patches, Clarke said. The patches themselves often have glitches that cause "unforeseen consequences" for companies when they install them, he said. As a result, many companies fall behind in patch deployment because they must first test the patches to see what additional problems they might cause.

"Rather than reject Bill Gates' statement that he's going to make security job No. 1, I welcome it," said Clarke. "And I'm going to hold him to it," he said, adding that other major software vendors should step forward with similar pledges.

Harris Miller, president of the Information Technology Association of America in Arlington, Va., said IT vendors have been moving aggressively on "baking in" rather than "painting on" security for a long time. However, "we are never going to have perfect software, any more than we have perfect buildings or perfect cars or perfect airplanes or any perfect products designed and built by humans," Miller said. "What is necessary is for consumers to understand that upgrades and patches will continue, just as cars get recalled to fix problems in the original vehicle."

But Clarke aimed his message at both sides of the supply and demand equation, particularly in the wireless access market. "Why is it that companies have sold [wireless] products that they know are not secure?" he said. "And why is it that companies have bought them? We all ought to shut them off until the technology gets better."

Although Clarke blamed the government to a certain extent for allowing security awareness to flounder, he also blamed telecommunications companies, Internet service providers and cable companies for offering broadband connections with little or no mention of the inherent security vulnerabilities in such connections.

Tens of millions of people hook up to the Internet via a broadband connection, such as a cable modem, but only one service provider currently warns customers of the risks involved and the need for a firewall to protect their sensitive data, said Clarke.

"[Broadband companies] want to make it cheap for people to become vulnerable to be hacked," said Clarke. "It's like selling a car without a seat belt." He urged ISPs to offer security options as part of a standard or premium subscription package.

"I think we have to play the role of Paul Revere in waking people up," said Clarke. "I don't think we can rely on the software companies to find their own vulnerabilities."

But the government may soon be doing more than playing Paul Revere. As Clarke prepares to release on Sept. 18 the National Plan for Protecting Cyberspace, he also may expand to all federal agencies a new U.S. Department of Defence policy that requires all new IT purchases to be made from a list of independently certified product lines. "The government buys a lot of software," said Clarke, referring to the US$20 billion budgeted for IT during the next three years. "That will create a market force that will drive security."

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.