Please wait while the page is being loaded Skip this advertisement >
Sunday | 23 November, 2008
CIO
The Bugs Stop Here
Don't Blame Microsoft. Don't blame the hackers. Blame yourself for insecure software. Better yet, Stop Blaming and start Moving towards operational Excellence
Scott Berinato 11 June, 2003 12:07:08

This past summer, a worm known a Slammer rattled the Internet violently enough to become what you might call a "CNN-level virus" - that is, it burrowed its way into the national consciousness. Nearly everything about the SQL Slammer was old. It was an old hack that exploited a year-old vulnerability found in an old target, Microsoft software. There was a patch to block Slammer that was six months old, and that patch suffered from an old patch problem: It was so kludgy to install that the patch needed a patch. Above all, the reaction to Slammer - the call to use the event to build security awareness - was so old it called Bob Hope "kid" . But this much was new: Everyone agreed that Slammer was your fault.

HOW TO SAVE $US60 BILLION

The old game was to blame Microsoft. "Microsoft did not protect its customers," read a letter to The New York Times after the Melissa virus hit in 1999. A year later, after the I Love You virus infected Microsoft Outlook, a Washington Post editorial stated: "This is a software development problem." The Nimda worm (2001), according to Forrester Research, required 625 combinations of patches applied to Microsoft's Internet Information Server. Nimda, along with its contemporary, the Code Red virus, eventually compelled Microsoft to implement and market Trustworthy Computing, an initiative aimed at helping Microsoft developers learn how to write secure code. Slammer, though, hasn't followed the old pattern. A developing consensual wisdom suggests that as woeful as Microsoft's products may be, CIOs have been equally sloppy. A February poll of more than 200 IT professionals, by antivirus company Sophos, showed that 64 per cent of respondents blamed their peers' lax security practices for Slammer. Only 24 per cent blamed Microsoft. The poll also revealed that only 43 per cent of the respondents said they subscribed to Microsoft's vulnerability mailing list, which provides early alerts of viruses in the wild. Twelve per cent said they relied on "mainstream news" - newspapers and TV - to learn about new viruses.

Three per cent said they "don't really hear about them at all". And 19 per cent said they patched software when they "got around to it". "I've got to look around at my comrades and ask: 'Why aren't you patching your systems?'," says Bob Ferderer, vice president of IT internal operations and security at CUNA Mutual Group, the US's largest financial service provider for credit unions, with 5000 employees and $US9.3 billion in assets. "There's a relationship between individuals not taking action and how these things spread out of control."

What frustrates Ferderer and other security experts is the fact that this seemingly intractable problem is actually quite tractable. The tools and strategies to prevent another Slammer are just waiting to be used. In fact, the number of tools and strategies available to you - and available at a reasonable cost - makes it inexcusable for any CIO to fiddle while the software burns.

There is, after all, $US60 billion on the table. A 2002 study by the National Institute of Standards and Technology (NIST) developed that number to describe buggy software's cost to the national economy. Improved software testing alone, NIST suggests, could shave $US22 billion off that. Why can't the software community motivate itself to grab all that cash? The answer lies in software culture.

Vendors, for the most part, value time-to-market over security. As long as they can get away with shipping buggy code, they will. Developers live by deadlines, which compel them to work fast. At the same time, they're being asked to provide ever more features.

And CIOs, as a group, have been passive, assuming there was little they could do to effect change.

They assumed wrong. In fact, a growing number of advocates believe CIOs should be leading the charge for secure software. "CIOs must take action," says Linda Northrop, director of the product-line systems program at the Software Engineering Institute (SEI) and co-author of Software Product Lines: Practices and Patterns. "I think CIOs have done a deplorable job matching their software decisions to business goals, especially in its security and quality. What we need from the CIO ranks are leaders." Northrop could be talking about Al Schmidt, vice president of IT and CIO of $US939 million Arch Chemicals. "What I've come to realise," says Schmidt, "is that security is really about operational excellence. So why wouldn't I jump on that? I mean, operational excellence - that's what I'm supposed to be doing, right?"

Featured Whitepaper Sponsors
Market Place
 
Featured Whitepapers

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00

    Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly.
  • +

    Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00

    Texas uni announces the Institute for Cyber Security.
    The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state.
  • +

    Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00

    Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions.
  • +

    International Challenges in PCI Security 20 November, 2008 09:15:00

    In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective.
  • +

    PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00

    Quality assurance plan targets security assessors and scanning vendors
    The PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

How to Beef Up Your Sales Pipeline

Our economy may be heading towards a recession. Sales rates are dropping. Promotional campaigns are proving less effective than you would like. So how do you continue to grow your business and bring home the sales in such an environment? Download this white paper now to find the answers.