Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Disclosure Plan Won't Help
Mark Rasch, 2003-10-20

Encouraging publicly-traded companies to disclose their cyber security efforts would only force them to choose between providing vague and useless platitudes, or specific and dangerous details.

Comments Mode:
Disclosure Plan Won't Help 2003-10-20
Anonymous (1 replies)
An alternative is a requirement that companies post statements of losses due to security failures in general figures such as manhours and costs of upgraded equipment. While it is less effective after the fact, a known track record can provide predictions about future success against attacks and fai...

[ more ]  [ reply ]
Disclosure Plan Won't Help 2003-10-24
Anonymous
I totally agree - corporations are the proverbial ostrich w/their head in the sand where security is concerned and they need to be held accountable!...

[ more ]  [ reply ]
Disclosure Plan Won't Help 2003-10-20
Montana Tenor (1 replies)
I agree with your article in such a profound way. Please let me suggest something that perhaps would be a useful concept.

DISCLAIMER: Many others may have suggested such a thing, and there may be something like this in existence so please excuse my ignorance.

Have the SEC (or some other cur...

[ more ]  [ reply ]
Disclosure Plan Won't Help 2003-10-20
Mark Rasch (1 replies)
I agree with the rating system, assuming that people can agree on a set of standards....

[ more ]  [ reply ]
Fort Knox is closed for a reason... 2003-10-23
HellCat
Mark,
Stick with the theme of your article. I was conviced.

If you start a rating system for companies then attacks will be focused on the lowest hanging fruit.

You cant tour Fort Knox because you will gain information about it's vulnerabilities. (assuming they have any gold left!)

...

[ more ]  [ reply ]
Disclosure Plan Won't Help 2003-10-21
Anonymous
I think you completely missed the mark.

It's true that a lot of companies write these attacks off as, "cost of doing business on the internet", and therefor don't keep accurate information on exactly how much these attacks cost them, but think about if they did.

ROI would be that much easier t...

[ more ]  [ reply ]
Disclosure Plan Won't Help 2003-10-22
Dennis Jugan
This is yet another case where corporate officers and boards of directors have shirked their responsibilities.

This is less an issue of technology, more an issue of good business practices - insuring against risk. Additionally, security is not a "one shot" issue. It's a process and a state of m...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus