Study: Hold Vendors Liable for Security Breaches

執筆者
Dennis Fisher
Dennis Fisher
Published: Jan 9, 2002
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A new report issued Tuesday by the National Academy of Sciences adds yet another voice to the chorus warning that the nations information systems are poorly protected.

The authors of this study go further, however, and suggest that the government should consider holding software vendors liable for security breaches in their products.

The report concludes that much of the blame for the sorry state of security in corporate and government networks belongs to administrators and CIOs who fail to implement readily available technologies such as firewalls and intrusion-detection systems or follow industry best practices.

“Many security problems exist not because a fix is unknown but because some responsible party has not implemented a known fix,” the report says.

But the authors also recommend that policy makers consider “steps that would increase the exposure of software and system vendors and system operators to liability for system breaches.” The report does not detail any specific sanctions for such offenses.

In researching “Cybersecurity Today and Tomorrow: Pay Now or Pay Later,” authors Herb Lin and Marjory Blumenthal looked back at several similar studies done by the Computer Science and Telecommunications Board to assess whether information security had evolved since their publication.

“The unfortunate reality is that relative to the magnitude of the threat, our ability and willingness to deal with threats has, on balance, changed for the worse,” they write in their new report. The CSTB is part of the National Research Council, which is, in turn, a member of the National Academy of Sciences. “From an operational standpoint, cybersecurity today is far worse than what best practices can provide.”

In addition to shouldering some of the blame for security breaches, the authors recommend that vendors develop better security interfaces for their products to simplify administration and conduct better testing of their products for security vulnerabilities.

Lin and Blumenthal also call for the more governmental funds for security research and development, a topic that has gotten some attention lately on Capitol Hill.

Dennis Fisher

Dennis Fisher

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。