jim_duffy
Managing Editor

Cisco’s secure development is still in the awkward teenage stage

Analysis
Aug 7, 20082 mins

Cisco’s chief security officer admits the company is in the “awkward teenage phase” when it comes to secure development lifecycles. In a wide-ranging interview with IDG News Service, John Stewart says Cisco hasn’t adopted a secure development process like Microsoft, and that testing is done at the end of the development process. “We’re figuring out from that data how do you go backwards into the definition process,” he says.

On the occasion in 2005 when Cisco sued security researcher Mike Lynn for revealing how it was possible to run unauthorized shellcode software on a Cisco router, Stewart says: “I think arguably we did some silly things, like trying to put the genie back in the bottle, which you can’t do. We were trying to do it for the right reasons: protection of intellectual property and our customers. But how it came out just completely went sideways. And, in many respects, we did it anonymously. It was ‘a Cisco spokesperson.’ We sort of hid behind an anonymity context , which I think really goofed everything. This is why I personally sponsored Black Hat at the platinum level ever since. Because I think we had some atonement to do and go, ‘Look, our bad. That was not the way to do that one.'” Since then, Cisco has been at pains to embrace the security research industry.

Cisco security is once again under attack at this week’s Black Hat/DefCon.

More from Cisco Subnet: 

* Lessons learned from a Cisco TelePresence customerAnother lost laptop: Who’s to blame – the TSA or VIP?Glimmer of hope in Cisco’s Q4Cisco in the cloudsCCIE water cooler gossip: Will the number of CCIEs double over the next 4 years? Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

*

Go to

Check out our latest Subnet: Google Subnet.