Skip Navigation

Life After Government
The latest on retirement issues

News Feeds

Online Directories
Browse for FREE, download vCards, and create customized mailing lists:
The Federal Technology Source: 3,000 of the most influential people in federal information technology.
The Chiefs Directory: 500 chief finance, information technology, procurement and personnel officers.


« Beware RFID | Main | Fight Over Classified-Info Trial Defense »

01:01 PM ET

Cybersecurity Impossible to Measure?

Last week, e-gov chief Karen Evans said that what keeps her up at night is cybersecurity. There may be a good reason to lose sleep, according Richard Ford of the Florida Institute of Technology.

In his article “Open vs. Closed”, which appears in Open Source Security, Ford concludes that cybersecurity cannot be measured. He argues that there are two possible ways to measure the security of a system:

•What are the chances that the confidentiality, integrity and availability of information of a system will be compromised?

•How many vulnerabilities are there in a product?

Ford says there is no way to quantify either measure. “Measuring security will mean different things to different people,” he writes. (Citation comes by way of John Scott, director of open integrations for RadiantBlue Technologies in Reston, Va., and author of the powdermonkey blog.)

More surprisingly, Ford comes to the same conclusion regarding open-source systems (for which the source code is public) and closed-source systems (in which the source code is kept secret). “The cases where one is clearly better than the other are few and far between,” Ford says.

True, open-source applications benefit from Linus’s Law (which states that given a large enough co-developer base, almost every bug will be found quickly and the fix provided by someone), but closed source “makes it expensive for anyone other than the developer to find those bugs.” Some applications benefit from full disclosure of their inner workings, some don’t.

Just another reason to lose sleep. Let us know about your cybersecurity concerns.

By David Perera at Link | Comments (0)

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)




©2007 by National Journal Group Inc. All rights reserved.