• On MovieTome: See the villain of IRON MAN 2!

September 22, 2003 4:42 PM PDT

Federal agencies tackle software security

  • 1 comment
Five federal agencies, led by the U.S. Department of Energy, plan to discuss a new set of government contracting practices that hold software makers accountable for making their products more resistant to viruses and hackers.

The Department of Energy on Tuesday will show off a "model contract" it signed "that demonstrates a new way for government to purchase software with security built in, enabling and requiring vendors to take more responsibility for both delivering less vulnerable systems and keeping them that way," according to a press release from the Center for Internet Security (CIS).

CIS, a nonprofit in Hershey, Penn., that advises members on computer security, is assisting the government in its quest for intruder-proof software. The center is organizing Tuesday's meeting at the JW Marriott Hotel in Washington, D.C.

The government effort could lead to improvements in computer security for all consumers of information technology, said Alan Paller, research director at the SANS (SysAdmin, Audit, Network, Security) Institute. "The government is going to use its procurement power to change the way vendors deliver their software," he said.

The SANS Institute, an information security research and training firm, works closely with CIS.

If anyone has the power to persuade the software industry to get serious about security, it's the federal government and its $50 billion-plus annual IT budget, Paller said. And with the recent wave of crippling worm attacks, it's about time it exercised that power, he said.

Key to the initiative is Karen Evans, chief information officer of the Department of Energy, Paller said. Evans was recently appointed administrator of information technology and e-government at the U.S Office of Management and Budget, a job she's scheduled to start next month. In her new position, she'll have oversight of IT purchasing activities across all federal agencies.

Software maker Oracle also is involved and will be speaking at the event, Paller said. A recent Oracle deal will be held up as an example of the new kinds of contracts the government is inking with software companies, he said.

An Oracle representative refused to confirm its participation in the initiative.

The other federal agencies leading the initiative are the Department of Homeland Security, the National Security Agency, the Department of Defense, and the General Services Administration, CIS said. The center expects 120 chief information officers and security specialists from government and business at the briefing.

Add a Comment (Log in or register)
Let's be honest..........
by Prndll July 31, 2004 10:42 PM PDT
If we are to be truly intellectually honest here.....

We must bring a crippling lawsuit against MicroSoft for making the Internet Explorer so vulnerable and easily hacked into. Windows itself is so wide open to attack it's not even funny. I realize this would eventually lead to a catastrophic meltdown of the global internet, but if the federal government really wants to solve the "real" problem---they must look to Bill Gates.
Reply to this comment
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Oracle (0.84%) 0.17 20.49
Dow Jones Industrials (-0.45%) -36.65 8,146.52
S&P 500 (-0.40%) -3.55 879.13
NASDAQ (0.20%) 3.48 1,756.03
CNET TECH (0.36%) 4.57 1,262.65
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right