Security survey and checklist
Attempt to gain better understanding of the costs of computer security incidents.
Businesses in the US have been urged to complete a survey issued jointly by the US Departments of Justice and Homeland Security. The aim of the survey is to gain a better understanding of the costs of computer security incidents.

The survey, which has been distributed to a wide range of industry sectors, covers a variety of security-related topics. For example, businesses are asked to describe the types of security incidents they have experienced, their current defence strategies and their concerns about information security. Encouraging businesses to reveal such sensitive information is notoriously difficult, but companies have been assured that the responses to this survey will be held strictly confidential, by law.
It is hoped that the results of the survey will provide enough information to establish some accurate data on the costs of computer security incidents and that they will help the federal government decide where to concentrate its resources in fighting cybercrime.
Meanwhile, the Department of Homeland Security's Cyber Consequences Unit has released the first draft of a checklist designed to help businesses focus on security best practices and on the consequences of security breaches.
The Cybersecurity Checklist identifies potential avenues for attacks and recommends ways to protect against them. The list concentrates on six areas of vulnerability: hardware, software access, software supply, network, automation and human operators. According to the Unit's director Scott Borg, the list provides specific guidance for businesses while also recognizing economic realities - including items that are desirable, but which may be difficult and expensive to implement. No date has been given for the final approval of the draft.
01 May 2006
Tags:
del.icio.us
digg this
Poll
Who in your company is responsible for installing software patches?Leave a comment

VB100 certification
The final VB100 of the year sees a double whammy of potential
pitfalls for our comparative participants - the
Vista operating system, which still seems shiny
and new as well as a little scary (to both developers and users), as well
as the x64 architecture, whose ostensible compatibility with standard
32-bit software belies oddities and intricacies that developers ignore at
their peril. The announcement of the test brought a few surprises, as
several regulars opted to skip this one, but the majority of veteran
competitors took part as usual, along with several newer faces, many of
whom look set to join the ranks of our regulars.
See full results.
Virus Bulletin currently has 148,292 registered users.

