10 February 2012

A Software Security Kitemark?

Last Thursday, the UK's House of Commons Science and Technology Committee published its report on malware and cyber crime following an enquiry and public consultation.

Title page on the website for the report by the 'Science and Technology  Committee' on 'Malware and Cyber Crime' published on 2 February 2012 and available at http://www.publications.parliament.uk/pa/cm201012/cmselect/cmsctech/1537/153702.htm

The committee welcomed the publication of the Government's cyber security strategy at the end of last year, but instead wanted to address the concerns of everyday internet users in its report. In particular the committee believes that better awareness of issues and solutions amongst computer users will provide the greatest benefits to society. It highlighted the plethora of onformation sources, and guidance that might be too technical to understand or too difficult to implement effectively.

The issue of a kitemark for software that meets certain security standards is raised again (paragraphs 67-68) although there is a concern that this might be more of a benefit to larger software development companies. The report suggests the ability and resource to "produce an online testing system already exists" (paragraph 69) and that the provision of an automated system to assess the security of software could be developed by Government or in partnership with private industry, or entirely by private concerns (paragraph 70).

Security labelling and the ability to automatically scan software for all security problems are not trivial issues, and we mustn't forget about design flaws and insecure deployment, but the committee is correct, consumers need better, trustworthy advice.

Posted on: 10 February 2012 at 07:45 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
A Software Security Kitemark?
http://www.clerkendweller.com/2012/2/10/A-Software-Security-Kitemark
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2012/2/10/A-Software-Security-Kitemark
Requested by 107.21.156.140 on Tuesday, 18 June 2013 at 22:08 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2012-2013 clerkendweller.com