, 2005-07-29
As the outrage and accusations, the knee-jerk shootings (and the knee-jerk legislation) continues to make press following the explosions and attempted explosions in London, the last thing that many of us need is another example where a situation needs to be solved by ill-conceived legislation that is proposed and passed in the heat of something big. Unfortunately, this is exactly what is happening on both sides of the CardSystems credit card compromise debacle.
Expand all |
Post comment

So perhaps the solution will be similar too. When IT security audits are mandated, then as a matter of good corporate governance they should be performed by an independent party which is strongly motivated and empowered to uncover faults. Naturally few companies would want to subject themselves to this sort of scrutiny, so it must be legislatively mandated, too.
By the way, concerning the security consciousness of bank IT people. I have worked with some bank IT people, and received detailed technical reports by or about others. It's a pretty mixed bag, same as everywhere. Some companies really are formidably good, others are very mediocre. The one thing they do all do well is the cornerstone of banking however; the ~appearance~ of security.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/343/32209#32209