In Brief

Eugene Spafford: Q&A

Professor Eugene Spafford knows a bit about security. And the Founder and executive director of Purdue University's Center for Education and Research in Information Assurance and Security (CERIAS) thinks we're doing it all wrong.

By Christopher Lindquist

Page 2

What I think is more likely to make a difference is insurance companies or lawyers are going to get involved. [Companies] are creating a monoculture that is more susceptible to the next big worm or next big break-in because everything is going to have the same set of vulnerabilities. If I was a stockholder in a firm that was doing that, and it got really badly hit by the next big virus or worm, I'd consider that negligent and possibly actionable. We've got years of experience showing us that these kinds of attacks are coming more and faster, that bugs are present. And here they are standardizing on a system that will be wiped out by the next thing that goes through. If that's not negligence, then I don't know what is.

Eugene Spafford

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors