* Application software breaches will lead to 'lemon laws', plus other predictions
endif; ?>The security experts at Unisys have looked into their collective crystal balls and come up with what they believe will be the 10 top security issues for the coming year. In no particular order, they are:
* Application software breaches will lead to “lemon laws.”
* Trusted networks involving business partners and others will grow as sources of risk.
* The mobile realm will continue to grow as a Petri dish for security incidents.
* Cyber attack styles will become virulent.
* Organized attacks by Internet desperados will increase.
* Enterprises will turn to proactive “defense-in-depth” as business needs drive security.
* Credit reporting agencies will become more involved in managing the consequences of identity theft.
* Adoption of federated architectures for identity and access management will accelerate.
* Enterprises will revisit role-based access control for identity and access management.
* Virtual directory technology will increasingly become a strategic component of identity integration projects.
A couple of these we can dismiss as “no-brainers”, some you may not have thought of, while others might need further explanation. Over the next few issues we’ll examine each in turn to see what impact it might have on your Windows network.
The first item on the list, “lemon laws” for applications, might need further explanation. According to Unisys Chief Security Advisor Sunil Misra, “As applications are brought closer to the edge of the Internet, it is only a matter of time in 2005 until an attack on a specific vendor’s application or database product causes damage that leads the customer to sue the software provider for the consequences of the security breach.”
According to Misra, this will lead application users to demand legislators to create laws that protect them from flawed software. Most state lemon laws are intended for the automotive market, protecting buyers from hidden damage and problems with automobiles while also extending warranties for unfixed problems. Of course, most software comes with no warranty.
Before the legislatures can create laws to extend the warranty on software, they will first have to create laws that require warranties. That won’t be easy, because no software company wants to provide any assurance that their product will perform the way you expect it to. So I don’t think we’ll see lemon laws for software by the end of 2005, although we might see the beginnings of a campaign to create them.
The second statement, “Trusted networks involving business partners and others will grow as sources of risk,” is in the no-brainer category. Digital interactions with business partners will continue to grow. As more partners and business processes are added, the complexity of the system grows. The more complex the system, the greater risk of a security hole. The real answer here is to work only with well-understood standards and protocols and insist that your partners do also. Anything else is just too risky.
We’ll look at some more of the top-10 in the next issue, stay tuned.




