★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/security_sources_article-8180.htmlNouvelle recherche | Portail wanayoo





Features: OSVDB: An Independent and Open Source Vulnerability Database
Guardian Digital Customers Protected From Linux Kernel Vulnerability
Newsletter: Linux Advisory Watch
Newsletter: Linux Security Week
Download EnGarde Today!


Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 

 
  News: Security Sources   10/23/2003 11:18
Disclosure Plan Won't Help

Published By: SecurityFocus
Posted By: Eric Lubow
10/23/2003

In an effort to shore up the security of the nation's critical infrastructures, the secretary of the Department of Homeland Security recently proposed that all publicly-traded companies disclose in their filings with the U.S. Securities and Exchange Commission precisely what they are doing to protect the security, confidentiality, integrity and availability of their electronic information and databases.

Harkening back to the end of the last millennium, Tom Ridge suggested in a speech before the Business Software Alliance that cyber security problems were similar to the problems presented to publicly traded companies before Y2K. Ridge suggested that, "... we need to talk about some kind of public disclosure. What are you doing about your security, physical and cyber security? Tell your shareholders, tell your employees, tell the communities within which you operate."

It's a worthy idea to ponder, but two underlying questions remain unanswered: are investors really going to make investment decisions based upon such disclosures, and wouldn't any meaningful disclosures provide hackers and criminals with a roadmap to vulnerabilities?

 
Pandora’s Box is open
Dec 26

Book Review: IPSec, The New Security Standard for the Internet, Intranets, and Virtual Private Networks, Second Edition
Dec 26

Security Awareness Tip: Continuity
Dec 26