Skip to main content

RSA Conference Europe 2005 - To regulate or not to regulate – Panel discussion

The general agreement was that it will get much worse than today, before it gets any better. How it will improve is much disputed: One side argues that government should intervene and hold software vendors liable for damages that are incurred due to faulty software. The other side refers to examples like US Sarbanes-Oxley Act of 2002 (SOX), where a few who misbehave draw a massive legislative backlash that has uncertain (and sometimes even unwanted) consequences. One example mentioned was the fact that parts of the widely agreed SOX-compliance implementation steps (whistleblower procedures) interfere with data protection laws in other countries (like France) or where the pressure of the public leads to laws that do not solve the problem, like the CAN-SPAM act. Industry representatives fear legislation as restrictions for innovation. Generally, the technology to make IT more secure is available, but there seems to be a market failure in allocating the costs to the entities that can actually change something. Today, security costs (costs for additional software, hardware, time to patch, control, clean up and/or re-install systems) are carried by the users of computers – be it individuals or corporations - instead of the providers of faulty software or services.

Comments

Popular posts from this blog

Sony is evil

I just so agree with Todd: Bad Company of the Year Award! : The company that I am putting at the top of my list is a 4 letter word so foul, that it has been banned from my home. I have asked my wife who is Japanese to refrain from buying any of their products for the next 5 years. The Bad company of the year is no other than SONY… Sony is just a big no-buy company. My girlfriend knows why Sony is evil and we both will rather buy a more expensive or less appealing product from a competitor. " Sony is evil " has only 726 hits on Google, but this will increase. Edit: More about the damage Sony does: Artists revolt against DRM Portable stereo's creator got his due, eventually

Why did Microsoft cripple Groove?

I'm currently trying to use Microsoft Groove 2007 as a collaboration tool to gather requirements. What I like about tools like Groove is: - You can open and edit an entry without having to start an additional application (like word, excel) - You can copy and paste pictures (screenshots) directly into an entry - You don't have to save and re-attach changed files - You can work offline - Groove works inside and outside of our network out-of-the-box - We have (as a Microsoft Gold Partner) 100 licenses available What I don't understand about the current offering is that a lot of tools available in the last version have been removed: The following tools and toolsets are no longer available for adding to new or existing workspaces : Contact Manager, Discussion, Document Review, Outliner , Task Manager, Text, Tic- Tac -Toe, Web Links, Welcome Page, Advanced Project Toolset , and Mobile Workspace for SharePoint . (Source: Microsoft Office Groove Help) There is also a large set ...

Passwords Alone Don't Protect Trade Secrets

Another proof that technology alone is not enough to keep important information secret; we'll have to establish policies and processes that explain people the meaning of tagging informaton confidential. Passwords Alone Don't Protect Trade Secrets : " A court ruled that simply password-protecting a file isn't enough to make it a trade secret. "