Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Selling through FUD and severity ratings
Uniqs:
206
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
RootKit Detectors - Not all = ! »
« Any opinions on McAfee VirusScan Enterprise Version : 8.0.0?  

EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

Selling through FUD and severity ratings

We've all seen it - the security alert that's rated critical by one vendor, medium or low by another.

This is a pretty good article from a solution provider's perspective on how the industry spins security alerts to sell or justify product. However, the problem also faces sysadmins and IT managers. The issue raised is that spinning and inflating(or deflating) risk ratings make prioritising difficult for system administrators, and difficult for solution providers and consultants to make recommendations to their customers.

Another point - for the home or SOHO folks with out-of-the-box apps in simple networks, patching is straight forward. However, those with customised multivendor applications and complex or critical networks need to be able to assign priorities for their QA teams. The marketing hype makes the tasks more difficult and expensive to maintain systems.

Symantec is mentioned prominently in the article, but a read shows they are only one of many who do this disservice to the IT community.

said by article :

Solution providers say that some vendors are using the alerts to promote their own self-serving interests, unfairly tarring rivals with higher vulnerability ratings and refusing to publicly air their own dirty laundry. They say what's needed is a "no spin zone."

But even without the spin, the vendors putting out the alerts often come up with widely differing scores on a particular vulnerability. This lack of consensus requires solution providers to spend valuable time calming their customers' fears and defending their vendor partners' products. Many solution providers told CRN they're often stuck in the middle between their vendor partners and customers after an alert is issued, which is putting their traditional role of trusted advisor to the test.

--
This space for rent
Forums » Up and Running » Security » SecurityRootKit Detectors - Not all = ! »
« Any opinions on McAfee VirusScan Enterprise Version : 8.0.0?  


Wednesday, 09-Dec 19:02:23 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [198] Sprint Sued For Distracted Driving Death
· [103] AT&T Launching New 24 Mbps U-Verse Tier
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [63] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [55] AT&T Hints At Usage-Based iPhone Data Pricing
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· MicroSoft Discontinues Sale of Windows 7 Family Pack in US [Microsoft Help]
· whole house ups [Home Repair & Improvement]
· [Rant] Campbell's Soup [Rants, Raves, and Praise]
· Internet access from TV [Verizon FIOS TV]
· TSN2 : Un rêve devenu réalité! [Videotron]
· Is sleeping similar to being dead? [General Questions]
· Forwarding previous owner's mail [Home Repair & Improvement]
· Windows 7 boot manager editing questions [Microsoft Help]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]