Organisation for Internet Safety launched

Group advocates limited public disclosure of software flaws

Written by James Middleton

A Microsoft-backed security organisation set up almost a year ago has finally had its formal launch.

Inaugurated last year at the Trusted Computing forum, the Organisation for Internet Safety (OIS) was charged with creating a set of guidelines for handling the disclosure of flaws and vulnerabilities in software.

Advertisement

The founders, which included Microsoft, @stake, Guardent, Bindview and Foundstone, favoured a standard that limited the public disclosure of security vulnerabilities.

It was announced today that Caldera/SCO, Oracle, SGI, Symantec and Network Associates have also jumped on board.

The organisation expects to release drafts of its guidelines in early 2003.

But when it was first suggested last autumn, the OIS was criticised by members of the security industry who suggested that a limited disclosure standard could be used as a stick with which to beat other researchers into line.

Some experts claim that limited public information will let vendors take their eyes off the ball when it comes to releasing patches.

The other side of the coin is that limited disclosure disarms the script kiddies and cyber vandals by not giving them an exploit on a plate.

John Pescatore, vice president for internet security at Gartner, said: "It's increasingly important to our critical infrastructure, as well as to individual computer users, that security vulnerabilities be avoided when developing software.

"But where they occur they need to be found and eliminated as effectively as possible. Industry consensus processes are a needed step towards making this happen."

A similar proposal, known as the Responsible Disclosure Process, which was more in favour of full disclosure, was rejected by the Internet Engineering Task Force (IETF) earlier this year.

The OIS proposal was taken on board by the IETF and will be opened to public review and comment before being considered for adoption as an official standard.

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Microsoft

Microsoft plans Silverlight 2.0 announcement

Web application tool revamp promised later today   More...

Stock prices

Security disclosures tip the stock market

Events such as Microsoft's Patch Tuesday could be used for...  More...

Blogs

Analyst predicts Web 2.0 fire sale

Prices for online apps could soon plummet, says Forrester   More...

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Primary Navigation