News
Black Hat: CSO Said Cisco Security Is Growing Ip
John Stewart doesn't talk like your typical corporate executive. He said that his company, Cisco Systems, has been lucky when it comes to security and that his company's Self-Defending Network marketing push has painted "a big bull's-eye" on its products
By Robert McMillan, IDG News Service (San Francisco Bureau)
IDGNS: Like Oracle's unbreakable Linux?
Stewart: In fact Mary Ann Davidson over at Oracle dropped me a note and said, "thank you very much for coming up with a slogan that takes the pressure off what we've done," [laughs] as if I had anything to do with the announcement.
And then third, we've really had a footprint grow. We got used in more and more places, and frankly for thinks we never imagined we'd be used for. We're transitioning health care communications, we're transitioning site-to-site communications for the military. We're doing all these wild things that 20 years ago we didn't think about at the time.
IDGNS: So did you do something like adopt a secure development lifecycles or change the way you built products? Stewart: We're not mature in this. We're in the awkward teenage phase. We're testing at the end of the development process and we're figuring out from that data how do you go backwards into the definition process. Now some definition happens anyway. So for example there are some baseline requirements of every product we built. However, I still say there's a lot to be learned. When you think you've got it right and you build it and you test it, the learnings from the test should benefit the next thing you build.
We haven't adopted a secure development lifecycle like Microsoft yet. We haven't nailed up equally on all product lines in a very consistent methodical measurable way, and that's why I say we're in that awkward teenage phase.
Other stories by Robert McMillan
Copyright 2009 IDG News Service, International Data Group Inc. All rights reserved.
Cisco
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



