Vendor Accountability Pushed

Vendor Accountability Pushed

Written By
Caron Carlson
Caron Carlson
Jun 30, 2003
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The greatest threat to the nations data networks today is not nascent cyber-terrorism lurking in the shadows but rather technology vendors unwilling to invest adequately in security, experts told Congress last week. Increasingly, industry insiders are seeking ways to make vendors accountable for their products.

As the Department of Homeland Security continues to shape its responsibilities, many in Congress, industry and academia are looking to the new agency to play a greater role protecting critical infrastructure, most of which is held by the private sector.

“There may come a time when a cyber-incident could also cost American lives, especially if there are concurrent attacks on physical and virtual infrastructures,” U.S. Rep. Mac Thornberry, R-Texas, said upon convening a hearing of the cyber-security subcommittee of the House Select Committee on Homeland Security.

Cyber-terrorism might one day be a problem, agreed Bruce Schneier, chief technical officer at Counterpane Internet Security Inc., but today, Schneier said, it is an unwarranted worry churned up by companies looking to stoke fear and by news media seeking sensational stories. The effects of cyber-attacks are far less terrorizing than they might seem, and worrying about cyber-terrorism detracts from addressing cyber-crime and basic security lapses, Schneier said in testimony before the subcommittee.

The CERT Centers at the Software Engineering Institute at Carnegie Mellon University, in Pittsburgh, found that security features in most products have not improved over the past few years.

Developers are not adequately applying lessons learned about the source of vulnerabilities, according to Richard Pethia, CERT director. Pethia told Congress last week that the government should consider including “code integrity” clauses in contracts to hold vendors responsible for defects.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.