|
By Forrester Research
Special to CNET News.com July 31, 2003, 5:45 AM PT Michael Rasmussen, Director, Forrester Research Microsoft and Cisco Systems announced major vulnerabilities last week.
Companies need a plan to respond and should not rely on products alone for protection. This is a people and process problem. The Microsoft vulnerability is a significant exposure into every operating system running the NT code base from NT to 2003. The Cisco vulnerability is an exposure that could crash every router. Vendor claims are far-fetched and provide a false sense of security. No vendor today resolves these vulnerabilities, except Microsoft and Cisco with the patches they implement. Security vendor solutions may hold back the evil hordes of hackers should they come knocking, but the deviants will break through given enough time and motive. The only true answer is to patch systems. Organizations should focus on the process and policy portion of security as much or more than the technology aspect. Do not put blind trust into security vendor claims of protection. Rather, honestly evaluate how the product works and the time it potentially buys you. Develop a patch management process based on business risk, so the critical business applications and support systems (network, desktop, for example) are expedited and patched in accordance with the risk the organization faces. © 2003, Forrester Research, Inc. All rights reserved. Information is based on best available resources. Opinions reflect judgment at the time and are subject to change.
| |||||||||||||||||||||
Breaking the digital gridlock
July 26, 2004
South Korea's digital dynasty
June 23, 2004
Bigger blue
June 14, 2004
Reality behind the politics
May 4, 2004
Playing for keeps
December 9, 2003
Corporate classrooms
November 11, 2003
Vision Series 4 (Part 1)
June 2, 2003
Digital remix
May 28, 2003
Mother of invention
April 11, 2003
It's a buyer's market
February 11, 2003
Nothing but air
February 3, 2003
Vision Series 3
December 2, 2002
A Mortal Microsoft
October 14, 2002
E-Terrorism
August 26, 2002
China's new dynasty
July 9, 2002
Vision Series: Tech chiefs dictate the future
June 10, 2002
Vision Series: Survey results
June 10, 2002
Sun's Java jigsaw
March 28, 2002
The Gatekeeper: Windows XP
October 17, 2001
A bitter pill
September 26, 2001
Privacy vs. safety
September 17, 2001