Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM

Outsourcing code puts security at risk

  • Email a Friend
  • Print Page
Outsourcing code puts security at risk
By Iain Thomson
Apr 8, 2008 8:43 AM
Tags: Outsourcing | code | puts | security | at | risk
The Quocirca report found that many companies are outsourcing more code development than ever before, and that nine out of 10 outsource more than 40 percent.

The National Institute of Standards and Technology reported recently that 92 percent of vulnerabilities affecting computer networks are contained in software applications.

However, when it comes to specifying outsourced code, one in five companies do not even consider security when designing applications.

Fran Howarth, principal analyst at Quocirca and author of the report, said: "The findings indicate that not enough is being done by organisations to build security into the applications on which their businesses rely.

"They are also entrusting large parts of their application development needs to third parties.

"This creates an even greater onus for organisations to thoroughly test all code generated for applications, without which they could be playing into the hands of hackers."

The top outsourcers are financial services organisations, 72 percent of which outsource more than 40 percent of new code development.

Only seven percent of utility companies outsource more that eight percent of code development.

Howard Schmidt, a board member at Fortify Software, and a former cyber-security advisor to the White House, said: "These survey results help explain the sudden rise in data breaches.

"It should serve as a wake-up call to any executive whose company sits on a pile of mission-critical application code."

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Risk Management Whitepapers