Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Selling through FUD and severity ratings
Search Topic:
Uniqs:
199
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
RootKit Detectors - Not all = ! »
« Any opinions on McAfee VirusScan Enterprise Version : 8.0.0?  
AuthorAll Replies


EGeezer
Summertime -
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

 Selling through FUD and severity ratings

We've all seen it - the security alert that's rated critical by one vendor, medium or low by another.

This is a pretty good article from a solution provider's perspective on how the industry spins security alerts to sell or justify product. However, the problem also faces sysadmins and IT managers. The issue raised is that spinning and inflating(or deflating) risk ratings make prioritising difficult for system administrators, and difficult for solution providers and consultants to make recommendations to their customers.

Another point - for the home or SOHO folks with out-of-the-box apps in simple networks, patching is straight forward. However, those with customised multivendor applications and complex or critical networks need to be able to assign priorities for their QA teams. The marketing hype makes the tasks more difficult and expensive to maintain systems.

Symantec is mentioned prominently in the article, but a read shows they are only one of many who do this disservice to the IT community.

said by article :

Solution providers say that some vendors are using the alerts to promote their own self-serving interests, unfairly tarring rivals with higher vulnerability ratings and refusing to publicly air their own dirty laundry. They say what's needed is a "no spin zone."

But even without the spin, the vendors putting out the alerts often come up with widely differing scores on a particular vulnerability. This lack of consensus requires solution providers to spend valuable time calming their customers' fears and defending their vendor partners' products. Many solution providers told CRN they're often stuck in the middle between their vendor partners and customers after an alert is issued, which is putting their traditional role of trusted advisor to the test.

--
This space for rent
Forums » Up and Running » Security » SecurityRootKit Detectors - Not all = ! »
« Any opinions on McAfee VirusScan Enterprise Version : 8.0.0?  


Tuesday, 10-Nov 19:23:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [113] Moto Sold About 100,000 Droids
· [93] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [64] Government Will Release Some Telco Wiretap Lobbying Documents
· [54] Verizon's Hanging Up On Rural America
· [34] Bill Would Force ISPs To Block Financial Scams
· [30] Verizon's Higher ETFs Annoy Senator
· [25] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [21] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Holy work line speeds!! [TekSavvy]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Framed for child porn 151; by a PC virus [Security]
· A fishy CRTC tarriff filed by bell? [TekSavvy]
· Are Gillette Fusion blades made of gold? [General Questions]
· Water heater pilot light won't light [Home Repair & Improvement]
· House inspector failed to find major gas leak [Home Repair & Improvement]