Security-Threat Basics Shouldnt Be Premium | eWeek

Security-Threat Basics Shouldnt Be Premium

Verfasst von
David Coursey
David Coursey
Oct 1, 2004
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren

Theres been a debate going on in the industry about whether its right for companies to charge for “premium” security-threat information. Me, Ive got my feet firmly planted on both sides of the issue, hoping they dont slide too far apart.

This discussion reminds me of something an open-source proponent once told me: “Information should be free, but my time isnt.” That concept should apply here as well.

Information about specific threats should be made widely available, quickly available, and available without charge. It is not acceptable to tell some customers first and others later. While that is bound to occur informally, it shouldnt become a revenue stream.

This prohibition shouldnt stop vendors from doing interesting things with threat information and charging for those services. As an example, lets look at how the National Weather Service makes its information available.

NWS provides weather data in a variety of formats and flavors. It does not charge for this information, although you may have to pay for the bandwidth to receive it. Third-party vendors, such as AccuWeather to choose a well-known example, repackage this information, add their own content and provide additional value-adds on a fee-for-service basis.

/zimages/2/28571.gifClick hereto read about a merger said to form the largest private security services provider.

Still, the most basic information remains available, for free, from many sources. You dont have to pay for weather information or forecasts, but there are reasons why you may want to.

This seems like a good model for threat information to follow, except that unlike the weather, where the federal government pays for the basic information collection and forecasting, security information gathering is dominated by the private sector, giving it more control.

As an ethical issue, I believe any organization knowing of a significant security threat has a responsibility to properly report it. Vendors have a responsibility to notify their customers or the broad user community, depending upon the nature of the threat.

Vendors responsible for providing solutions to these threats have a responsibility to make them available on a timely basis. While it is acceptable to roll out solutions first to most-vulnerable customers, I dont believe there should be discrimination based on willingness or ability to pay.

Advertisement

/zimages/2/28571.gifCheck out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

/zimages/2/77042.gif

Be sure to add our eWEEK.com Security news feed to your RSS newsreader or My Yahoo page

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.