Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • IT Management

    Report Takes Software Processes to Task

    Written by

    Peter Coffee
    Published April 22, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      I feel as if I could get an entire years worth of columns, or perhaps even build my next career, out of the material in a Task Force Report that was issued at the beginning of this month by the National Cyber Security Partnership.

      The NCSP formed in response to last years White House National Strategy to Secure Cyberspace, creating five task forces, including one on “Security Across the Software Development Life Cycle.” It is that particular group whose 123-page report seems like almost enough to spend my next several dozen weekly columns addressing.

      Coincidentally, the Task Force report emerges on the heels of Richard Clarkes reappearance on the national scene as a voice for the urgent need to attend to computer systems security as a national priority. Some have deprecated Clarkes concern with this subject during the end of his time in the present Bush administration as a sign that he was not aware of worse threats to the nation, but he may wind up looking smarter than his critics on this point. The situation is not merely serious, but is one that will take a long time to correct.

      /zimages/1/28571.gifFor insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Especially interesting in the Task Force report, and something Ive not seen before, is a sober and objective appraisal of just how poorly we train software developers in the discipline of writing software to be secure. “Few people would accept medical treatment,” the report opines, “from practitioners who were originally economics graduates, operated on people in their spare time, and went through a rapid training program to become doctors. But as a nation, the United States has taken exactly this position with regard to engineering software systems that run critical infrastructures upon which many lives depend.”

      The report does acknowledge the multidisciplinary nature of software security, noting that “While a doctoral level mathematician with expertise in number theory can do some limited work in theoretical cryptography and protocol analysis, and a person with a doctorate in computer engineering with a specialization in computer architecture can design new structures to support operating system enhancements, these and many other sub-specialties are required for the systems level understanding required to meet requirements for high surety systems.”

      This breadth, the report argues, means that “there is a need for a national community of professors with the combined understanding of these issues and the collaborative structure required to apply these experts in concert.” A commitment to have just one such research professional in every U.S. state, with support for graduate students and conference participations and related costs, would represent a national initiative costing some $50 million per year, estimates the report; thats cheap compared to the cost of just one significant, large-scale security breach.

      To those who argue that software as a discipline evolves too quickly to be tracked by a formal educational infrastructure, the report points out that “for the last 30 years, India has put forth a concerted effort to provide high quality university education in software design to their young people. As a result, India produces programmers that make fewer errors per line of software code than programmers trained in the United States.” High-quality software can certainly be insecure, but it seems to me that low-quality software cannot possibly be secure no matter what mechanisms it attempts to use.

      Some observers address the Task Force report at much briefer length than my imagined years worth of columns. Ian Grigg is the Australian co-founder of Systemics Inc., described by its Web site as “a technology company specialising in e-payments and financial cryptography.” The company appears to have a deliberately obscured location, with its “Contact Us” Web page offering no physical address and advising interested parties that questions “should be sent to admin at the normal place.” The company also has a colorful history that sounds more drawn from paperback fiction than from paperless banking, with business disputes involving lurid reports of seduction as a tool of a partner firms business development practices.

      Be that as it may, Griggs “Financial Cryptography” Weblog calls the Task Force report on life-cycle software security “a scary document.” He calls the reports recommendations a collection of “calls to certify this, verify that, and measure those”; in particular, he takes the report to task for its dismissive statement (on page 6, which is the eighth page of the Task Force PDF document hyperlinked near the top of this column) that “No processes or practices have currently been shown to consistently produce secure software.”

      One might note that the Task Force is co-chaired by one Microsoft staffer and includes two others as members—the fact that much of the worlds most popular software is obviously being produced by insecure practices does not prove that no secure practices exist. Research conducted by @stake Inc. has documented the effects of design-time choices and has shown their potential for a fourfold reduction of application vulnerability.

      But Grigg is up against credible experts like Gary McGraw, CTO at Cigital Inc., who assisted in writing the Software Process Subgroup portion of the Task Force report that includes the statement to which Grigg takes exception. While McGraw has certainly suggested approaches to elevate the security of the software development process, it is not clear that any organization has yet succeeded in building its process on those foundations.

      Is your enterprise the existence proof, or can it become one soon?

      Tell me what you wish we could learn about secure software processes at [email protected].

      /zimages/1/28571.gifCheck out eWEEKs Developer & Web Services Center at http://developer.eweek.com for the latest news, reviews and analysis in programming environments and developer tools.
      Be sure to add our eWEEK.com developer and Web services news feed to your RSS newsreader or My Yahoo page: http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo2.gif

      Peter Coffee
      Peter Coffee
      Peter Coffee is Director of Platform Research at salesforce.com, where he serves as a liaison with the developer community to define the opportunity and clarify developers' technical requirements on the company's evolving Apex Platform. Peter previously spent 18 years with eWEEK (formerly PC Week), the national news magazine of enterprise technology practice, where he reviewed software development tools and methods and wrote regular columns on emerging technologies and professional community issues.Before he began writing full-time in 1989, Peter spent eleven years in technical and management positions at Exxon and The Aerospace Corporation, including management of the latter company's first desktop computing planning team and applied research in applications of artificial intelligence techniques. He holds an engineering degree from MIT and an MBA from Pepperdine University, he has held teaching appointments in computer science, business analytics and information systems management at Pepperdine, UCLA, and Chapman College.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.