All the latest UK technology news, reviews and analysis

Radical security development rethink urged

by Robert Jaques

14 Apr 2003

Be the first to comment

  • Tweet this

Traditional technology management methods are not capable of dealing with development of mission-critical security projects effectively, an industry firm claimed today.

Benjamin Jun, vice president of Cryptography Research, warned that fundamentally different engineering processes are needed because traditional methods have meant managers can create systems that are impossible to check and difficult to repair.

"Designers working on mission-critical security must focus on minimising the odds of security flaws, yet most engineers have had little, if any, training to teach them the skills necessary to do this effectively," said Jun.

"Although it's impossible to prove that a system will be secure, many managers fail to take even simple steps towards reducing the possibility that they'll ship a disaster.

"By failing to consider how engineering choices affect the system's life cycle, managers can create systems that are impossible to validate and impractical to repair."

Jun believes the security technology industry is a field still in relative infancy, relating security development processes with more mature high-risk fields, such as nuclear power plant operations and surgical medicine.

"While students at every medical school meet weekly to discuss surgical errors and methods for preventing them, I don't know of a single computer science programme that meets even once a semester to discuss software bugs or practical ways to avoid them," Jun said.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Digital Account executive 25k Fulham

Digital Account Executive Fulham, London 25k A great...

Oracle Apps DBA

Our global consultancy client currently seeks a number...

Support Analyst x 1/2 (Apple Mac OSX/Windows) - Bristol/Bath

Support Analyst x 1/2 Skills: Apple Mac OSX, Windows...

Network Consultant - London - 55-65k

Network Consultant - London - 55-65k My client are...

To send to more than one email address, simply separate each address with a comma.