On TechRepublic: Male bashing in the workplace
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 1:
Solving Half the Equation is Still Only Halfway There
Open source projects benefit from the public and collaborative nature of the community of users and developers associated with the project. The most popular open source projects are very stable, being used and debugged by tens of thousands of developers, and have been broadly implemented by F100 corporations and worldwide governments for years. This announcement reiterates the widespread use of open source as commercial service providers step in to provide packaging, training and support for the most popular solutions on the market.

But the most popular open source projects (e.g. various Linux distributions, JBoss, MySQL, etc), are just the tip of the iceberg of typical enterprise open source use. Open source projects can now be found at the operating system level, embedded as key components within applications, and as stand-alone applications. The embedded components are some of the most widely used open source projects that no one (outside of the engineering team) has ever heard of ? GNU GetOpt, OpenSSH, zlib, etc. Enterprise security and IT teams should be just as conscientious about services and support for those projects.

For many of these type of open source components, no mechanism is in place by which to notify customers of updates and push them out automatically to users. This puts the burden of responsibility on the user to monitor whether there are security patches or newer versions of the open source project available. That's hard to do when their use goes undocumented and undetected.

In our continuing efforts to make open source implementation a successful (and secure) process in the enterprise environment, Palamida uncovers and inventories undocumented open source code and its known vulnerabilities. After evaluation their individual risk profiles, companies should ask themselves whether they really know everything they are using and whether they would stake their jobs on its security.


Melisa LaBancz-Bleasdale, Palamida
Posted by: Melisa@...   Posted on: 11/16/07 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Solving Half the Equation is Still Only Halfway There  Melisa@... | 11/16/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement
  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More