On TV.com: BATTLESTAR Galactica Maxim Photoshoot
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Feb 17, 2005 4:20:00 AM

SAN FRANCISCO--A panel of security experts on Wednesday debated the merits of regulating the software industry as a way to curtail software flaws--and hence reduce the volume of virus attacks.

With software flaws serving as the open door to viruses and worms, a panel of industry experts at the RSA Conference here pondered whether it's time to regulate software companies. The experts were mixed on the effectiveness of such a plan and whether it could be undertaken without crimping innovation.

"The issue is not to regulate or not," said Harris Miller, president of the Information Technology Association of America. "Our industry is all about innovation, and my concern with regulation is it's often the enemy of innovation."

In that same vein, Rick White, chief executive of technology advocacy group TechNet, said the industry should come together and develop guidelines for best practices on developing software with minimal flaws, rather than imposing regulations.

"Congress will never solve the problem as well as the people who work in the industry," said White, a former congressman from Washington state.

But other panelists were not as sure.

Dick Clarke, chairman of Good Harbor Consulting and former presidential special adviser on cybersecurity, noted that efforts to have industries develop guidelines and follow through have failed in the past. For instance, Internet service providers did not adhere to self-imposed principles, even after Michael Powell, head of the Federal Communications Commission, threatened to regulate their industry if they did not abide by those guidelines, Clarke said.

"Powell bluffed them. They knew it, and now he is leaving office," Clarke said.

Other panelists, such as encryption expert and author Bruce Schneier, also called for more action in prompting software vendors to vet through their code before releasing it to the market.

"If we make it in their best interest to do this, then it will happen. You need to find a set of financial incentives," Schneier said. "Regulations would increase the cost of not doing security, and that would increase security (testing)."

Companies that take the time to test the security of their software before releasing it are at a disadvantage because of higher costs and potential late arrival to the market, he said.

Additional financial incentives may come from customers demanding a certain level of security testing from a vendor, before agreeing to sign a contract to purchase their products, Schneier said.

In offering a post-Sept. 11, 2001, warning, Clarke said: "Regulation is neither good nor bad...but the industry should bear this in mind. After we have an incident, regulations will be much worse."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 25 Talkback(s)
Outstanding post.
Rarely do I see a poster in this forum with as good a grasp of the market forces at work. (Read the rest)
Posted by: No_Ax_to_Grind Posted on: 02/20/05 You are currently: a Guest | | Terms of Use
Regulation will fix software bugs....  rock06r | 02/17/05
Well, since it's *shiny*...  Martin Marvinski | 02/17/05
Regulation no, Accountability yes  prong@... | 02/17/05
Accountable - yes  jsjag1 | 02/17/05
Regulation will come if Software Industry does not police it's self.  xshakes | 02/17/05
It already has!  Joe Blow_z | 02/17/05
I vote with you  BXLE | 02/17/05
Lemon Law  Joe Blow_z | 02/17/05
Regulations breed inefficiencies. Plus, as little  bjbrock | 02/17/05
No problem?  BXLE | 02/17/05
I have confidence that the market is self-regulating.  Yen_z | 02/17/05
Microsoft has licensed Roxio burning for MediaPlayer...  Anton Philidor | 02/17/05
I would agree with you that for the technically inclined...  Yen_z | 02/17/05
They see the problems they incur as technology...  Anton Philidor | 02/17/05
In reply...  Yen_z | 02/17/05
You forget.  slopoke | 02/17/05
I think this has now changed.  Yen_z | 02/17/05
IBM tips the balance, yes.  Anton Philidor | 02/17/05
Well, your take on things and my take on things...  Yen_z | 02/17/05
Outstanding post.  No_Ax_to_Grind | 02/20/05
Like it would do any good  qcimushroom | 02/17/05
You want regulation - fine, here is what the industry response will be  Confused by religion | 02/17/05
Your Right  qcimushroom | 02/17/05
Oh, you want to run *that* software. No way!  No_Ax_to_Grind | 02/19/05
Regulators get lobbied by mega-corps  Knorthern Knight | 02/17/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here