Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Selling through FUD and severity ratings
Search Topic:
Uniqs:
205
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
RootKit Detectors - Not all = ! »
« Any opinions on McAfee VirusScan Enterprise Version : 8.0.0?  
AuthorAll Replies


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

 Selling through FUD and severity ratings

We've all seen it - the security alert that's rated critical by one vendor, medium or low by another.

This is a pretty good article from a solution provider's perspective on how the industry spins security alerts to sell or justify product. However, the problem also faces sysadmins and IT managers. The issue raised is that spinning and inflating(or deflating) risk ratings make prioritising difficult for system administrators, and difficult for solution providers and consultants to make recommendations to their customers.

Another point - for the home or SOHO folks with out-of-the-box apps in simple networks, patching is straight forward. However, those with customised multivendor applications and complex or critical networks need to be able to assign priorities for their QA teams. The marketing hype makes the tasks more difficult and expensive to maintain systems.

Symantec is mentioned prominently in the article, but a read shows they are only one of many who do this disservice to the IT community.

said by article :

Solution providers say that some vendors are using the alerts to promote their own self-serving interests, unfairly tarring rivals with higher vulnerability ratings and refusing to publicly air their own dirty laundry. They say what's needed is a "no spin zone."

But even without the spin, the vendors putting out the alerts often come up with widely differing scores on a particular vulnerability. This lack of consensus requires solution providers to spend valuable time calming their customers' fears and defending their vendor partners' products. Many solution providers told CRN they're often stuck in the middle between their vendor partners and customers after an alert is issued, which is putting their traditional role of trusted advisor to the test.

--
This space for rent
Forums » Up and Running » Security » SecurityRootKit Detectors - Not all = ! »
« Any opinions on McAfee VirusScan Enterprise Version : 8.0.0?  


Saturday, 05-Dec 09:20:34 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [93] The Bandwidth Hog Does Not Exist
· [84] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [79] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Farewell [Bell Canada]
· Why do you switch distros? [All Things Unix]
· Windows 7 boot manager editing questions [Microsoft Help]
· DNS options, what are YOU using? [TekSavvy]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Road Runnner up to 50 mbps is ready ! [Road Runner]
· UPS - What do you people think happened? [General Questions]
· [Wireless] Linksys WMP54g v4.1 and Windows 7 x64 [Linksys]