In Brief
Eugene Spafford: Q&A
Professor Eugene Spafford knows a bit about security. And the Founder and executive director of Purdue University's Center for Education and Research in Information Assurance and Security (CERIAS) thinks we're doing it all wrong.
By Christopher Lindquist
December 01, 2003 — CSO — Professor Eugene Spafford knows a bit about security. And he thinks we're going about it all wrong. Founder and executive director of Purdue University's Center for Education and Research in Information Assurance and Security, he was named to the President's Information Technology Advisory Committee in 2003 and has worked on many security books and articles.
CSO recently talked with Spafford about technology, complexity and the shape of security to come. CSO: Do we need to make wholesale changes in how we approach security
Eugene Spafford: We need to make some significant changes
One of the chief enemies of good security is complexity. Complex systems are difficult to build and configure correctly, and they're difficult to understand and operate. Many of the weak points we have now are the result of systems with too much functionality that either isn't needed or can't be secured properly. Hardware is cheap enough that we should be able to afford to buy an extra box or two and isolate and contain failures.
The trend toward all-in-one systems came about decades ago when equipment was very expensive, and we wanted to run everything on the same box. We argue now that we can reduce the training if we have only one type of system or we can reduce the number of patches. But if your system is exceedingly simple to operate
There are a number of languages that could be developed that are considerably safer for running most of our applications. And we should start putting some energy and thought into creating testing tools and diagnostic tools for what we build. Having thousands of flaws per year that need to be patched is ridiculous.
Eugene Spafford
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



