On mySimon: Stephen King - Salem's Lot
BNET Business Network:
BNET
TechRepublic
ZDNet

October 9th, 2006

Don't blame the vendors for sad state of security

Posted by Richard Stiennon @ 9:01 am

Categories: Spyware

Tags:

Roger Grimes over at InfoWorld posted a sobering column. He is frustrated by the fact that no vendor sells a product that defends against all attacks. Or, as he puts it:

There is no single product that will protect you against 100 percent of the threats that it claims it will prevent.

 

I agree completely with those statements and I like Roger's example of being able to own any corporate network with a simple email:  

Just send a spam e-mail to corporate employees entitled "Pending 2006 Layoffs" pretending to be from the CEO, and have it contain one of the many MS-Office zero days with an unscannable remote access trojan. I do it for a living, and rarely do I have to wait more than a few minutes for complete network access.

But Roger's frustration should not be targeted at the vendors. We are all engaged in a continuing struggle that needs constant vigilance and investment to fight. A single vendor is not going to solve all our problems, despite the now common advice from industry analysts to buy from big name AV companies.  As long as Microsoft continues to issue buggy software, as long as new products and services are developed, as long as business itself is dynamic and changing, there will be new threats, new attacks, and the need for new defenses. 

 Don't waste your breath moaning about it. Get out to the front lines and start defending your networks!

Richard Stiennon is an industry consultant. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 4 Talkback(s)
yep
Of course a single solution cannot provide 100% coverage.

http://dcssec.blogspot.com/2006/10/layering-controls-100-compliance-3.html... (Read the rest)
Posted by: jbcupps Posted on: 10/25/06 You are currently: a Guest | | Terms of Use
Just Switch to Linux  bcroner | 10/09/06
Simple mind - simple logic  crayolakidd | 10/09/06
Me thinks you doth protest too much  Hrothgar - PCLinuxOS User | 10/09/06
yep  jbcupps | 10/25/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    Favorite Links

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
    • More from IBM
    • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
    • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
    Click Here