Security group preps IT shops to ask vendors 'nasty questions'
- 16 March, 2010 00:49
- Comments
The Jericho Forum, which advocates improving e-commerce security through knowledge that network perimeters are fading, says organizations need to ask themselves and their vendors tougher questions.
To assist, the 60-member forum Monday issued its "Self Assessment Scheme".
"We took our best practices and turned them into generic examples," says Paul Simmonds, CISO at pharmaceutical firm AstraZeneca, a Jericho Forum member.
The self-assessment, though touted as a "set of nasty questions to ask your security vendors," is more a set of strong security preferences and attributes that vendors would have to acknowledge whether their products support.
For example, according to Jericho Forum's principle No. 4, "Devices and applications must communicate using open, secure protocols."
Under the assessment guideline, a vendor product must first earn a baseline "acceptable" rating by being able to claim a positive response to several statements posed as a question, such as whether the protocols are "built-in" or "added-on," and whether they’re "appropriate to the task." If the product gets that far, it has a chance to earn a higher "Good [Best Practices] rating by passing a review that asks whether there are "cost implications (licensing, royalty, or other) for using any of the protocols," among other questions.
The Jericho Forum, operated under the aegis of the Open Group, was founded in 2004 mainly by large international companies that were finding their online efforts hampered more than helped by traditional firewalls and so sought to draw attention to the need for innovations in security approaches.
The goal of the Self Assessment Scheme is to "expose shortcomings in the features" that vendors "may be claiming their offerings provide," the Jericho Forum states, adding vendors may want to review it to be able to provide responses to customers.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Five Things You Need to Know About Your Users Before You Deploy Business Intelligence
- Oracle BPM Suite 11g: BPM without Barriers
- Why Two Thirds of Enterprise Architecture Projects Fail
- Oracle SOA vs. IBM SOA - Customer Perspectives on Evaluating Complexity and Business Value
- Top 5 Threat Protection Best Practices
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Phones are distractions during catch-ups
-
Google's Sidewiki lets people post comments about Web pages
-
Forrester Research - Exploring the Benefits of End-to-End Convergence of Data Center Networks
This paper examines the benefits to be gained through convergence; how to overcome the organisational barriers to adoption and the catalysts for adoption of converged architecture. -
Oracle SOA vs. IBM SOA - Customer Perspectives on Evaluating Complexity and Business Value
The Service-Oriented Architecture (SOA) model has become the cornerstone of business computing. Its ability to greatly accelerate the development of business-critical applications promotes business agility, decreases time-to-value and total cost of ownership (TCO), and greatly increases the efficiency and strategic value of IT. SOA implementations tend to be complex, IT decision makers should carefully consider their choice of a SOA platform in terms of its ability to simplify the fundamental development, deployment, and management tasks involved. Read on. -
Optimizing Storage and Protecting Data with Oracle Database 11g
This paper focuses on key Oracle Database 11g capabilities that help IT departments better optimise their storage infrastructure, enabling administrators to deliver a cost-effective, scalable data management platform that is easy to manage, reduces costs, and protects data while continuing to deliver the performance and availability that today’s businesses require.
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Dummies®
-
Office 2007 for Dummies
-
Teach Yourself Visually Windows 7








Comments
Post new comment