Tuesday, April 21, 2009

JSF supporting systems hacked

I don't know how well the JSF support systems are maintained and monitored, even the most secure systems are crackable.

JSF program systems hacked


That being said there are still far too many reports of military, infrastructure, and corporate systems being broken into and sensitive data being stolen. If you consider that only a great minority of actual events are reported and many may not even have been discovered then you must come to the conclusion that there is a real problem with how security is currently being implemented and maintained.

Security is not an add-on feature, it must be part of the solution during the entire life cycle. Failure to consider a broad scope of security issues in at every step of a system from design to decommissioning can only result in failure.

Most security specialists working in production environments should primarily be auditors and advisers; the real security is executed by engineers, admins, and users. Managers, train your non-security folks on security regularly. Failure to do so could land you or your company in the next newspaper story.

No comments: