Monday, 28 September 2009

Information Security Is Not Just An IT Thing

Every industry is complex and has facets which only become obvious to experienced, well trained professionals. Complexity is in the blood of information security, which requires detailed knowledge of software, hardware, networking, compliance, legislation, industry standards and training. In a perfect world whole teams of specialists should be employed to manage this enormous challenge, but all too frequently security is thought of as one of those 'IT Things' that should be handled by who ever is changing the toner cartridges.

Sunday, 20 September 2009

Who Is Looking at The Code?

At a Microsoft hosted security event earlier this year, Ed Gibson the Chief Security Advisor to Microsoft UK asked a rhetorical question about open source software - "Who is looking at the code?"This question made the audience pause.

Open source software is any computer program where the underlying code is legally available for review. Frequently the code is available as a requirement of development such as for compatibility testing, sometimes the code is available so that third parties can be wowed by the code and just occasionally companies are forced into releasing code because they didn't read all of the terms and conditions when they should have done (see the Forbes article Linux's Hit Men).

Monday, 14 September 2009

The Inevitability of Down Time

It's been a bad week for service providers, which knocks on to a bad week for the people who support their products in client organisations. Problems happen, but how a company handles problems and how it communicates what happened can display their real quality.

On Monday the 7th of September online payment processors SagePay (the rebranded Protx) suffered an outage affecting all 25,000 clients and untold end users. Late in the evening of Wednesday the 9th of September the mobile phone company Orange experienced an outage which affected some of their mobile data customers and their landline broadband customers. This combined with a reportedly unrelated Blackberry data service outage during the same period to leave users only able to access email from their computers.