ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

US agencies demand tighter software security

Alorie Gilbert CNET News.com

Published: 23 Sep 2003 11:14 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Five federal agencies, led by the US Department of Energy, plan to discuss a new set of government contracting practices that hold software makers accountable for making their products more resistant to viruses and hackers.

The Department of Energy on Tuesday will show off a "model contract" it signed "that demonstrates a new way for government to purchase software with security built in, enabling and requiring vendors to take more responsibility for both delivering less vulnerable systems and keeping them that way," according to a press release from the Centre for Internet Security (CIS).

CIS, a nonprofit organisation that advises members on computer security, is assisting the government in its quest for intruder-proof software. The centre is organising Tuesday's meeting at the JW Marriott Hotel in Washington, D.C.

The government effort could lead to improvements in computer security for all consumers of information technology, said Alan Paller, research director at the Sans (SysAdmin, Audit, Network, Security) Institute. "The government is going to use its procurement power to change the way vendors deliver their software," he said.

The Sans Institute, an information security research and training firm, works closely with CIS.

If anyone has the power to persuade the software industry to get serious about security, it's the federal government and its $50bn (£30bn) annual IT budget, Paller said. And with the recent wave of crippling worm attacks, it's about time it exercised that power, he said.

Key to the initiative is Karen Evans, chief information officer of the Department of Energy, Paller said. Evans was recently appointed administrator of information technology and e-government at the US Office of Management and Budget, a job she's scheduled to start next month. In her new position, she'll have oversight of IT purchasing activities across all federal agencies.

Software maker Oracle also is involved and will be speaking at the event, Paller said. A recent Oracle deal will be held up as an example of the new kinds of contracts the government is inking with software companies, he said.

An Oracle representative refused to confirm its participation in the initiative.

The other federal agencies leading the initiative are the Department of Homeland Security, the National Security Agency, the Department of Defense, and the General Services Administration, CIS said. The centre expects 120 chief information officers and security specialists from government and business at the briefing.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
63 out of 124 people found this useful


Full Talkback thread

1 comment

  1. It seems that Microsoft had better start digging f... adebayo omo-dare

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Service Desk Support / Support Technician - Frankfurt, Germany

Role: Service Desk Support / Support Technician - Frankfurt, Germany Location: Frankfurt, Germany Salary: Very Competitive Type: Permanent Serco ...

Project Manager - Newcastle - EDS Excellent Salary + Flexible Benefits Package

Job Description: Project Management Tasks: Experienced in Software / Application development Project Management experience through the whole system ...

Biostatistics Team Leader

To represent the Biostatistics department within the company and with interactions with client companies and regulatory agencies, as required. ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation