Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Security bosses feel patch pain

Subject: [ISN] Security bosses feel patch pain
Date: Tue, 23 Nov 2004 05:24:38 -0600 (CST)
http://www.fcw.com/fcw/articles/2004/1122/web-ciso-11-22-04.asp

By Florence Olsen 
Nov. 22, 2004

A survey to be released today cites patch management as the No. 1
concern of chief information security officers in the federal
government.

The survey, conduced by O'Keeffe & Co. for Intelligent Decisions, a
federal systems integrator, highlights the day-to-day concerns of
federal CISO's and the effects that the Federal Information Security
Management Act has had on them professionally.

"The fact that they're saying software quality and patch management
are way up there in terms of their pain ? that's a pretty clear
message to the vendor community that we need to figure out how to
solve that problem," said Ted Ritter, director for cybersecurity at
Intelligent Decisions.

In the survey results, achieving FISMA compliance and avoiding a
compromised network tied for second place among the concerns of
federal CISOs.

The survey results also showed CISOs spending a large portion of their
time on administrative activities related to FISMA compliance, with
the burden falling heaviest on those whose average full-time staff
size is 2.6 employees. Federal CISOs who control a budget of less than
$500,000 spend 45 percent of their time on FISMA compliance reporting
and only 15 percent of their time on network security monitoring and
inventory control.

By contrast, CISOs who control a budget of more than $10 million spend
27 percent of their time on FISMA compliance reporting and an equal
amount of time on network security monitoring, systems administration
and trouble shooting.

The telephone survey was based on interviews with 25 out of 117
federal CISOs.



_________________________________________
Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - 
http://www.osvdb.org/

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Security bosses feel patch pain, InfoSec News <=