ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

BP hits out at security standards

Tom Espiner ZDNet.co.uk

Published: 25 Nov 2005 16:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Energy giant BP criticised the security record of application vendors on Tuesday, which it said was pushing it towards open source software.

Software firms are not keen on cooperating on security, as it would mean making their systems interoperable, said Paul Dorey, BP's director of digital security.

"We need interoperability. I'm concerned about lack of competition, but I'm more concerned about interoperability. Open source has a role to play, as well as academia," said Dorey, speaking at the launch of the latest SANS Institute security research on Tuesday.

"At BP we are trying to go for open protocols. At some point in the future open source will become key." Dorey added.

Government officials also expressed unhappiness with vendors' security records, saying the network perimeter of government and business is not secure enough.

"We need fit for purpose architectures. One of the dirty secrets of security is that we rely on the network perimeter — but these dams leak," said Steven Marsh, the Cabinet Office's director of information assurance.

The government says it wants to promote Internet community action and mutual support to tackle security issues..

"We want to encourage Internet communities to set up systems whereby they communicate with each other within the community for mutual support," said Roger Cummings, director of National Infrastructure Security Co-ordination Centre (NISCC).

"The inexorable march of Internet technology will come to dominate all electronic communications. Network convergence will happen at a global and a local level, merging onto a single platform, and it will all be connected to the dirty outside world of the Internet," said Cummings.

Good procurement is the answer
Today, application security is inadequate because it "relies on the good will and good citizenship of technology vendors to ensure computers are secure," said Alan Paller, director of the SANS Institute, a training body for information security professionals.

"It's easy for vendors to ensure security when the software is being built. Microsoft and Apple should sell secure systems to begin with," according to Paller.

Paller called for governments and businesses to force vendors to supply more secure systems by simply refusing to buy them if they don't meet security requirements.

"US Air Force chief information officer John Gilligan said in 2003 that it costs the military more to clean up the mess left by Microsoft than buying the software to begin with. He put $500m on the table, and specified safe configurations on every system. By doing that he has lowered the patch testing costs by $100 million or more. The Air Force now requires all software it buys to be built to run on the safe configurations developed by Dell," said Paller.

"That's the message for business — make your systems more secure by procurement, not regulation. We've been buying stuff that's broken, but you don't have to spend the money that way," Paller added.

"I put this to Congress, and they spluttered and said 'I don't understand why we're not doing this already.' It's the first time I've seen Congress think they can actually do something useful," Paller said.

The government agreed that vendors needed to guarantee security, but added that security needed to be dealt with within a company's perimeter too.

"The security of a product needs to be out of the box. There also needs to be firefighting within a company in this increasing risk environment," said Cummings.

Company directors also need to recognise the importance of security, and make decisions concerning it.

"There needs to be recognition that information risks are important at board level. The board needs to be losing sleep if they're not confident in their information assurance," said Marsh.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
56 out of 137 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Campaign Manager

Sets campaign parameters on a daily basis - Ensures campaigns are executed as per agreed business requirements - Monitors campaigns throughput taking ...

Graduate Technical Project Support

As well as a competitive salary, Morrisons offers a range of benefits including stakeholder pension, life assurance, annual profit share and staff ...

QA Team Leader

QA software testers; - Manage the quality assurance of all new and existing products developed by the internal software development team or provided ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments