Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Software with Security in Mind: Page 2 of 2


Step By Step

As IT professionals, we realize patch management is a good first step. We need to use chroot and other sandboxing technologies to put applications into areas where they can do little harm if attacked. We must limit access to applications. We must protect ourselves from problems we ourselves cause--a misconfiguration or misinstalled program can contribute to an attack as readily as a bug can.

In the end, we are at the mercy of our software developers. It's our responsibility to tell them what we need and expect--that secure software is a requirement, not a nicety. It's our butts on the line, and we must kick and scream until the developers change their ways, or we must find someone else who will meet our needs.

Mike Lee is NETWORK COMPUTING's editor. Write to him at [email protected]