SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Tools and Languages

Why 'Black Hats' are winning app security war

Why 'Black Hats' are winning app security war

By:  Derek Slater  On: 17 Nov 2008 For: CSO (US)(NA) 

The proliferation of non-technical CIOs is making it harder for IT to communicate the security risks says James McGovern of the Open Web Application Security Project (OWASP)

I wanted very much to write a column about how we've reached a turning point regarding application security.

It wasn't that I thought one particular cataclysmic event has changed our course for the better. Rather, it was an accumulation of smaller observations and developments:

-- Writers and bloggers like Jeremiah Grossman, Hugh Thompson,Gary McGraw (and many others) have done great work shedding light on the topic.

-- OWASP, the has established chapters around the world, and its Top Ten Vulnerability list is ever more widely disseminated.

-- (ISC)2 recently set forth a new certification covering application lifecycle security issues.

-- Both source-code analysis tools and application vulnerability scanners and services can help find flaws on either end of development and deployment. These technologies are maturing quickly.

-- And if there is a big one, it would be the application security requirements in version 6.6 of the PCI Data Security Standard, which went into effect this past June and essentially calls for you to use the two approaches mentioned in the preceding paragraph (if not both).

That's a good bit of app sec activity. Taken together, I thought, maybe it constitutes a quorum of some sort?

Alas, as I tried to kindle the flames of a warm and fuzzy analysis of these signs of progress, James McGovern was standing by with a bucket of cold water. McGovern is leader of the Hartford chapter of OWASP. His simple response to my hypothesis: "I think the black hats are winning."

McGovern gives three reasons:

One, companies tend to work toward consensus, which takes time. Even if an application security vulnerability becomes visible to attackers and defenders at the same time, he argues, the attackers are much quicker on the draw while the defenders go through the process of discussion and prioritization;

Two, he says outsourced application development creates some obstacles; offshore shops in particular are governed by the rule of margins, so they are discouraged from adding security steps (and therefore time, and therefore cost) to the development process;

And reason three is a bit of a kick in the seat of the pants: McGovern says that technical security is "a hard thing to participate in for non-technical people," and that the proliferation of CIOs with non-technical backgrounds has made it harder to communicate technical risk.


Sign up for our Newsletters












Print |  Views: 555   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Derek Slater Derek Slater is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Stimulus package could boost IT job prospects
Stimulus package could boost IT job prospectsThe outlook for IT jobs in 2009 may not be as bad as it seems. In fact, a US federal economic package might even create new positions, according to analysts
Open source gaining traction in U.S. government, says survey
Open source gaining traction in U.S. government, says surveyAccording to a recent survey, more than half of all U.S. government executives have rolled out open-source software at their agencies, and 71 per cent believe their agency can benefit from open-source software.
Plugging the MFP security gap
Plugging the MFP security gapWhen developing IT security plans, companies can easily overlook one seemingly harmless but vulnerable piece of equipment: The multifunction printing device. Don’t let MFPs become your achilles heel.
Deperimeterization and realism
you gotta love this industry for the ever-evolving vocabulary. my neologistic experience this week was stumbling upon the word "deperimeterization." the actual concept isn't new to me, but there's an awkward grace to the expression that appeals. (i approached computerworld editor shane schick -- a bit of an eye-roller when it comes to such ham-fisted constructions -- and he bet me a bag of chips
Comodo touts security platform capabilities
comodo security solutions says its endpoint security manager platform will save both time and money for smb it administrators. the jersey city, nj-based online security software ve
Back to the future
learning from the past is critical in helping prevent the repeat of past mistakes.   studying new research is important in helping to adopt new practices when available and appropriate rather than h

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.