There is hardly a dearth of groups worrying about cybersecurity. Yet another report on the subject was released this month by yet another group few people had heard of. The report has raised eyebrows by suggesting that buyers should be able to say they want vendors to offer secure systems.Last month I wrote about the purposely toothless recommendations that the National Cyber Security Partnership (NCSP) is releasing. Since I wrote that column, the NCSP has released an additional report that fits the same mold as the previous two.This other new report, however, is from the Corporate Information Security Working Group (CISWG), which Rep. Adam Putnam (R-Fla.) established late last year.The group was established in lieu of introducing legislation, strongly opposed by the business community, that would have forced publicly traded companies to include a report of an information security audit in their annual Securities and Exchange Commission filings. I guess the business community worried that such audits might reveal that corporate indifference to information security issues is far too common. The threat of the truth can make some people nervous. The CISWG report consists mostly of four lists of recommendations and some supporting information, including a good list of information-security-related references. The recommendations, if fully implemented, might not be quite as toothless as the NCSP recommendations. That might or might not be a good thing.The Awareness and Education Recommendations include developing materials that would make it clear to home users, and others, including corporate executives in small and large businesses, that information security is good stuff. The Best Practices Recommendations, among other things, feature establishing an international “umbrella organization to oversee the further development of IS guidance for organizations and users of all sizes and types” with representatives from just about every walk of life. Sounds like a perfect way to ensure that nothing gets accomplished.The Incentives-Liability/Safe Harbor Recommendations include throwing the insurance industry at the problem by asking it to “modify the degree of availability and the cost of cyber-risk insurance protection based on the degree that the company exercises cyber-risk best practices.” This presumes the insurance industry would be better at picking effective best practices than the high-end auditing firms have been – a presumption I have a hard time supporting. But making it harder for a company that doesn’t even try to address information security problems to pass the risk of its inaction to an insurance company is not a bad idea.Finally, the Procurement Practices Recommendations include the suggestion that has attracted the most attention from the news media. After recommending that the U.S. government mandate minimum configuration security standards for government-purchased equipment, the working group recommends providing “an exemption from U.S. anti-trust laws for critical infrastructure industry groups that agree on obligatory security specifications for software and hardware they purchase.”This seems like the approach of the anti-virus industry: Most vendors can only fight yesterday’s problem because that is all they know. These vendors also give a good road map of ignored areas.Disclaimer: Harvard does not confine history to the history department, but is not constrained by it in other departments. Still, the university has not commented on this report. Related content news analysis IBM cloud service aims to deliver secure, multicloud connectivity IBM Hybrid Cloud Mesh is a multicloud networking service that includes IT discovery, security, monitoring and traffic-engineering capabilities. By Michael Cooney Dec 07, 2023 3 mins Network Security Network Security Network Security news Gartner: Just 12% of IT infrastructure pros outpace CIO expectations Budget constraints, security concerns, and lack of talent can hamstring infrastructure and operations (I&O) professionals. By Denise Dubie Dec 07, 2023 4 mins Network Security Data Center Industry feature Data centers unprepared for new European energy efficiency regulations Regulatory pressure is driving IT teams to invest in more efficient servers and storage and improve their data-center reporting capabilities. By Maria Korolov Dec 07, 2023 7 mins Enterprise Storage Green IT Servers news analysis AMD launches Instinct AI accelerator to compete with Nvidia AMD enters the AI acceleration game with broad industry support. First shipping product is the Dell PowerEdge XE9680 with AMD Instinct MI300X. By Andy Patrizio Dec 07, 2023 6 mins CPUs and Processors Generative AI Data Center Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe