SD TIMES BLOG
dworthington

The infrastructure crisis

by David Worthington 11/20/2008 12:16 PM EST

There is an infrastructure crisis in the United States beyond our decaying bridges, roads and sewer systems: Systems that are vital to commerce and the every lives of the American people are insecure and vulnerable to attack.

Yesterday, we published a story about Green Hills Software obtaining a high security accreditation from the US National Security Agency. Naturally, Green Hills had an interest in convincing me that its Integrity operating system was the right medicine.

Granted, Integrity's merits have been proven. It is only 4000 lines of code, and it leaves far less surface area exposed for attack than mainstream operating systems. The fact that it is available is a good thing.

I am by no means an expert on infrastructure security, but I have to question why critical systems in the public sector were not hardened in the first place. While using a secure operating system is only part of the answer, software like Integrity should already have been widely used, and there should not be a security 'crisis.'

There were guidelines for designing secure software in the past, but I am told that they were difficult to obtain. The Trusted Computer System Evaluation Criteria, known as the Orange Book, was held too close to the military's vest. The NSA's National Information Assurance Partnership (NIAP), which tested and certified Integrity, is a more recent development.

Security has long been an after thought in software, and vulnerabilities were not given equal treatment as other defects. Bridges are designed to meet certain tolerances: Why wasn't the software that we rely upon? The nation's neglect of the public sector would be unfathomable if it wasn't reality.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Share this link: http://www.sdtimes.com/blog/1240

Tags: ,

Comments

Add comment


 
 

biuquote
  • Comment




 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Are you at risk for burnout?
Burnout is a severe problem and it can strike at any time. Here's how to tell if you are nearing the edge.
02/09/2012 02:16 PM EST

Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb