Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Feds Talk Security

    Written by

    Caron Carlson
    Published July 22, 2002
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Tired of waiting for a consensus among corporate CIOs and security experts on how to lock down their networks, a group of federal agencies and industry organizations last week released guidelines of their own. The move, however, is being seen by some as the first step toward governmental regulation of security standards.

      While government officials have been quick to say the Consensus Baseline Security Settings for Microsoft Corp. Windows 2000-based machines are only suggestions, security experts remain split, calling the list either a helping hand or heavy-handed.

      “Assuming that the new security settings are well- thought-out, I think this is a good idea,” said Phil Zimmermann, chief cryptographer at Hush Communications Inc., in Vancouver, British Columbia, who fought a long-running battle with the government over efforts to export his Pretty Good Privacy encryption software. “For too long, Windows machines have been wide open to attack. Anything that will tighten up millions of Windows machines will improve our collective immune system.”

      The guidelines are suggested base-line settings for machines running Windows 2000.

      They were developed jointly by the Presidents Critical Infrastructure Protection Board, the Center for Internet Security, the National Security Agency, the General Services Administration, the National Institute of Standards and Technology, the Defense Information Systems Agency, and the SANS Institute. The group also released a small vulnerability scanner to check each machines settings.

      While the guidelines are not yet mandatory for government agencies, most departments intend to implement them and expect their private-sector contractors to do likewise.

      “I think CIOs within government are expected to implement these base lines,” U.S. Air Force CIO John Gilligan said at the unveiling of the standards at the GSA here last week. “As we begin to establish these benchmarks, they would become effectively mandatory across the federal government.”

      Regardless of the governments intentions, some users are still not entirely comfortable with Washingtons involvement in the security industry.

      “Having minimum standards of security is a good thing,” said Fred Dunn, Short Message Service administrator at the University of Texas Health Science Center, in San Antonio. “Having the [government] set those standards, well, well have to wait and see. Earlier, the breach of a single system used to cause problems for one or a few, but internetworking and the complexity of operating systems has changed the rules.”

      Richard Clarke, President Bushs special adviser for cyber-security, emphasized, however, that the federal government does not have the legal authority today to impose technology requirements on the private sector. “Were not going to have federal requirements as the solution to the private sectors problems,” he said at the announcement.

      Nevertheless, the collaborating organizations emphasized that last weeks announcement is only the beginning and that they intend to develop standards for a wide range of software products, including firewalls, Oracle Corp.s database software and Microsofts IIS (Internet Information Services) Web server.

      “Were forming an Oracle database team, and we have yet to get into printers, faxes and scanners,” said Clint Kreitner, president and CEO of CIS, in Bethesda, Md., adding that the standards are not likely to break applications.

      Officials at Oracle and Microsoft welcomed the development of guidelines for their products and said that just the governments adoption of the settings could change things for the better.

      “The government is one of the largest consumers of IT software and can change the market and persuade vendors to change their practices,” said Mary Ann Davidson, chief security officer at Oracle, in Redwood Shores, Calif. “They should be very demanding. I think enterprises probably will adopt [the guidelines] just because of the caliber of the entities involved in drafting them.”

      “The government agencies involved have a lot of security experience, and I think its very appropriate for them to get involved,” said Steve Lipner, director of security assurance at Microsoft, in Redmond, Wash. “Anything the country does to improve security is a good thing. It should get the attention of IT managers.”

      Oracles Davidson said that the establishment of some consensus guidelines will help take some of the burden of security off the backs of administrators and return it to the vendors.

      “The administrators shouldnt have to do a lot of work in securing our products because they never have enough time,” Davidson said. “Im really interested in [the coalitions] take on what are the most important things to lock down. We want our products to be secure by default. If its not, we want to change it. You need ultimately to have a flexible configuration scheme so you can ask the customer whether they want the really paranoid installation.”

      Caron Carlson
      Caron Carlson

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×