• On TV.com: Sexy summer bodies photo gallery
November 1, 2007 5:18 AM PDT

No fear at IBM? Add open source to the mix

by Matt Asay

Dan Farber reports on IBM's $1.5 billion security push, dubbed "an enterprise free of fear." (Note to IBM: "Free from fear" would be the more direct way of saying it.) But IBM, like others, is approaching security as code an enterprise would layer on other code, and processes on top of that code, rather than something inherent in the code itself, as Stuart McIrvine, director of IBM?s Corporate Security Strategy, relates:

"Our approach is that security is kind of broken. Companies are leaving security in the hands of IT and operations people, looking at servers, databases and putting up firewalls and updating antivirus signatures. But they have no real view of what they are protecting from a business strategy viewpoint, understanding the core objectives and risks to meeting those objectives."

IBM?s aims to engage the business side to surface key processes and systems, and from a top down to understand objectives and risk, and then to mitigate the risk with the available budget. "We are in the mitigation business, helping companies decide what risks to accept."

With all due respect, IBM's strategy should also attack "fear" and "risk" at one critical foundation of the problem: the code itself and how it is developed.

Without ensuring a code-level view of the products it is using to enhance security, IBM is only going halfway. Microsoft has long prided itself on the resources it was throwing at improving its security and, to its credit, its products have gotten better over time. But arguably Microsoft's products would have benefited from peer review, and not simply internal review. IBM is no different.

If an enterprise wants to lower its risks associated with software, it should ensure it's buying into a community, and not merely some binary 1s and 0s. It should also demand that it have access to the source code to modify as needed (though yes, few will do so, those who do act as a surrogate to those who don't or or won't).

In short, IBM should take its security story one step further and provide open access to its code. Done right, it's a key way to ensure that a customer's code is closed.

Matt Asay brings a decade of in-the-trenches open-source business and legal experience to The Open Road, with an emphasis on emerging open-source business strategies and opportunities. Matt is vice president of business development at Alfresco, a company that develops open-source software for content management. He is a member of the CNET Blog Network and is not an employee of CNET. Disclosure.
Recent posts from The Open Road
What soccer team would your company be?
Open-source licensing: Your mileage may vary
Open source to shape cloud computing, but not dominate it
Off-topic: Why can't I have this job?
Legalized drugs, now open source. Those crazy Dutch!
Will 'good enough' virtualization topple VMware?
Linux community codes around Microsoft's FAT patents
As Mozilla 'upgrades the Web,' Microsoft must upgrade its pace
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About The Open Road

Matt Asay brings a decade of in-the-trenches open-source business and legal experience to the Open Road, with an emphasis on emerging open-source business strategies and opportunities. Matt is general manager of the Americas division and vice president of business development at Alfresco, a company that develops open-source software for content management. He is a member of the CNET Blog Network and is not an employee of CNET. Disclosure.

Add this feed to your online news reader

The Open Road topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right