Czar sets out security stall

Microsoft chief UK security officer speaks exclusively to Network News

Paul Allen

The man charged with leading Microsoft's efforts to secure its software has vowed to put the interests of enterprises above the company's consumer customers.

Stuart Okin was appointed last week to the newly created post of UK chief security officer. His role is to bring together the raft of security initiatives sparked by Bill Gates's promise to clean up the company's act on security.

Advertisement

Microsoft CTO Craig Monday recently said that reaching a trusted state with security, reliability and privacy could take up to 10 years. "I support that for consumers, but for enterprises we need to do it as quickly as possible," said Okin.

He would not commit to a specific timescale, but said the company was in consultation with customers and developer forums to ascertain the key short-term goals.

Okin said it was difficult to gauge the company's progress. "We can't just go to vulnerability tracking sites to judge whether we're being effective. If we find more vulnerabilities it could be an indication we're doing well, providing they're fixed quickly."

Okin renewed Microsoft's attack on those who publish the details of vulnerabilities as soon as they are discovered.

"It is irresponsible for any finder to issue details until a patch is available. It's like leaving home, leaving the door open and announcing it with a megaphone," he said.

But Deri Jones, security services director at NTA Monitor, said that published vulnerabilities gave suppliers an incentive to get things done faster, and that network managers had a right to know.

"Honesty and openness mean things get fixed," he said. "If Microsoft and other vendors fixed vulnerabilities in a timely fashion, then that argument would hold water.

"If you don't publish the information, then sysadmins don't have the choice to turn off a feature. It goes round the hacker community fast enough, and network managers should be able to make an informed choice."

Comment on this story

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

US security crackdown loses support

People want expanded snooping powers curtailed

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation