December 4, 2003 4:32 PM PST

Cybersecurity task forces push for results

SANTA CLARA, Calif.--Five working groups formed at the National Cyber Security Summit released initial reports that focus on delivering concrete results within a year, task force leaders said Thursday.

The working groups have pledged to release white papers by March 1, 2004, that outline their recommendations for securing businesses and consumers and creating more secure software. The next meeting, tentatively set for September 2004, will be the deadline for each group to deliver at least some results.

"A concern is that if we were to meet in (a year), can we show progress?" said Mary Ann Davidson, chief security officer at database maker Oracle and the co-chair of the Technical Standards and Common Criteria Task Force, one of the five working groups. "Even if we make recommendations, we should prioritize, and one of the priorities should be showing results in a year or less."


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


The quick deadlines are a nod to the urgency expressed by policy makers and consumers. Critics have snubbed the United States' cybersecurity policy--the National Strategy to Secure Cyberspace--as largely voluntary and lacking regulatory prescriptions. The National Cyber Security Summit, sponsored by four industry associations, showed that businesses have at least taken some of the criticism to heart. The four organizations that sponsored the Summit were the Business Software Alliance, the Information Technology Association of America, the TechNet lobbying group and the U.S. Chamber of Commerce.

Security experts formed five groups to focus on specific problem areas: creating awareness in home computer users and small businesses; establishing a cybersecurity early warning system; making information security part of corporate governance; advocating technical best practices for security; and pushing security improvements into the software development process.

Despite the pressure to deliver, reigning in the groups to focus on concrete ideas that could be implemented quickly was a task, Oracle's Davidson said.

"It took us a while to home in," she said. "We had a number of people that said, 'I want to make the Internet a safe place.' Well, I want world peace, too, but you need to focus a bit."

Davidson's group focused on ways of expanding technical specifications and government evaluation programs to apply to more information technology products and give consumers a way to evaluate security products. Some sort of expanded certification could help them decide, she added.

"Right now, it's caveat emptor, but customers don't know what to emptor," Davidson said.

Moreover, software makers may be required to use certain types of tools to drum out well-known vulnerabilities automatically during the development process in order to qualify for certain levels of certification. The problem right now is that many of the tools don't exist or are expensive. Yet, a public effort to create such tools is needed to stamp out security flaws that crop up because of developer ignorance or mistakes.

"If we can stamp out small pox, why can't we get rid of buffer overflows?" she said.

The Corporate Governance Task Force has already released a 75-question survey for chief executives to take to their information managers in order to get a clear idea of the company's security. The group believes that the answers will offer a baseline snapshot of the security of the average U.S. business.

While producing visible results is important, a member of the Early Warning System Task Force stressed that the group wanted to make sure that the project was done right.

"Time lines are important and necessary, but people are coming together to build something new and necessary," said participant Gerhard Eschelbeck, chief technology officer of vulnerability assessment firm Qualys.

That group plans to create an advisory system that goes beyond the computer emergency response teams that currently warn people and companies of new vulnerabilities and major incidents.

"Early warning is not about identifying a new worm a few minutes before it hits but about a new flaw or threat before it happens," he said. "You want to spot the signs and signals leading up to the next attack."

One notable group of developers appeared to be left off the invitation list for the event, however. Red Hat, SuSE Linux and other Linux companies weren't represented in the work groups.

Oracle's Davidson conceded that future meetings should include Linux companies. "That's a point we need to consider," she said. "We need to make sure that if we are going to do this, that we also include open-source vendors."

See more CNET content tagged:
cybersecurity, security, Oracle Corp., U.S.

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    Dell's new CFO Brian Gladden has said that the company "more work to be done," to improve profitability and decrease costs. The Wall Street Journal is reporting that the company is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Negative Approach

    Online content and services via game consoles will generate $8 billion in revenue in 2013

    The revenue possibilities in gaming continue to grow, at least for the big console manufacturers.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Was EarthLink's failed citywide Wi-Fi a blessing in disguise?

    Wireless Philadelphia, the nonprofit charged with providing broadband bundles to low-income families in Philadelphia, may be better off in the long run without EarthLink.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Behind the prototyping of 'Spore'

    Many of the components of Will Wright's highly anticipated evolution game started out as small concept projects that are now available to the public.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • The Cheapskate

    Record TV in style with a refurbished TiVo HD, $179.99 shipped

    TiVo is offering refurb HD units for cheap, though you'll still have to pay for the TiVo service.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.