Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -1 articles for you...
82

Department Of Energy Mandates Enhanced Oracle Database Security

The department of energy has done something unusual for a federal agency. It has become an example of excellent cyber-security practice. It has done this by pressuring Oracle to elevate security in its 9i database product--in the process, taking software out . . . . The department of energy has done something unusual for a federal agency. It has become an example of excellent cyber-security practice. It has done this by pressuring Oracle to elevate security in its 9i database product--in the process, taking software out of the shadows of "as is" licenses and putting it in the spotlight of a government procurement action. DOE's action could begin a process that improves the security of the technologies available to the public and private sectors alike. To win this open-ended deal, Oracle promised to deliver its database in a secure configuration and took responsibility for the security of the software going forward. Future patches must be delivered quickly and cannot create new problems or vulnerabilities if Oracle wants to continue getting paid. It's the kind of vendor commitment that every enterprise merits but that only the $59 billion IT buying power of the federal government can effect right now. The link for this article located at eWeek is no longer available. . The energy sector establishes a benchmark by insisting on advanced safety measures from Microsoft for fortified cloud infrastructure.. Database Protection, Cybersecurity Standards, Government Procurement, Vendor Accountability. . Anthony Pell

Calendar%202 Oct 07, 2003 User Avatar Anthony Pell Government
82

Civilian Agencies Push for Unified Tech Certification Standards

If civilian agencies join the national security community in limiting technology purchases to items that have gone through independent evaluation, it could spur vendors to submit more products for certification, officials testified today before a House subcommittee. . .. If civilian agencies join the national security community in limiting technology purchases to items that have gone through independent evaluation, it could spur vendors to submit more products for certification, officials testified today before a House subcommittee . The national security community and the Defense Department already require any product with a security component, from a firewall to an operating system, to go through an independent evaluation that includes the Common Criteria, a set of tests to make sure that security-related products actually perform the way a vendor states. As agencies come together to use the Common Criteria to craft protection profiles -- descriptions of security characteristics an agency would like for its IT components -- the number of certified products is increasing. The trend would move even faster if civilian agencies were to join in the demand, said Michael Fleming, chief of the Information Assurance Solutions Group in the National Security Agency's Information Assurance Directorate. The link for this article located at FCW is no longer available. . Government departments can enhance their technological credentials by integrating defense protocols, urging suppliers to meet standards.. Tech Certification, Procurement Standards, Common Criteria, IT Security, Vendor Compliance. . Anthony Pell

Calendar%202 Sep 18, 2003 User Avatar Anthony Pell Government
82

SBA and DOD Integrate Databases for Efficient Contractor Registrations

The Small Business Administration and the Defense Department last week took the first step toward completing the Business Partner Network for government contractors. SBA integrated its small business database, PRO-Net, with DOD's Central Contractor Registration system. . .. The Small Business Administration and the Defense Department last week took the first step toward completing the Business Partner Network for government contractors. SBA integrated its small business database, PRO-Net, with DOD's Central Contractor Registration system . PRO-Net serves as agencies' small-business procurement resource, and the CCR is the central repository of information about contractors doing business with DOD. Small businesses can now enter their information in both databases simultaneously. CCR will rely on PRO-Net as the authoritative source for vendors certified under SBA's small-business contracting programs, such as 8(a) and HUBZone for historically underutilized businesses. Eventually the CCR will become the Business Partner Network, a key part of the Office of Management and Budget's Integrated Acquisition Environment, an e-government project. The network will then serve as the single point of registration and validation for vendors. Agencies also will have to register with the network to make interagency transactions. The link for this article located at GCN is no longer available. . The Federal Trade Commission and Department of Health integrated systems to enhance the regulatory process for consumer safety measures.. Small Business Integration, Government Contractor Registration, SBA PRO-Net, DOD CCR, E-Government Procurement. . Anthony Pell

Calendar%202 Dec 26, 2002 User Avatar Anthony Pell Government
81

DoD Procurement Balancing Open Source And Proprietary Software Debate

The Initiative for Software Choice, a software industry trade group whose members include Microsoft, Intel and Cisco, has advised the U.S. Department of Defense not to adhere to a policy that promotes open source software at the expense of proprietary software. . . . . The Initiative for Software Choice, a software industry trade group whose members include Microsoft, Intel and Cisco, has advised the U.S. Department of Defense not to adhere to a policy that promotes open source software at the expense of proprietary software. The group has issued a report arguing that the DoD's evaluation of software purchases should not be influenced by "a preconception that open source software is somehow inherently more secure." "ISC is against government policy that restricts procurement to any kind of software," ISC executive director Bob Kramer told NewsFactor. He noted that the group has no prejudice against any software, but that government procurement policies "should focus on obtaining the best software to solve the problem." The ISC Mission The Washington, D.C.-based ISC was founded in May. The group states it is "dedicated to the principle that governments should procure their software products on their merits rather than categorical preferences." Therefore, its goal is to "educate policymakers about the need to remain neutral about the governmental purchase of software." Toward that goal, the ISC recently issued a report that countered another report written by defense contractor MITRE. The MITRE report noted that open source software "plays a more critical role in the [DoD] than has generally been recognized," and that the DoD has 115 open source applications with 251 identified uses. It then concluded that open source products are a viable alternative to proprietary products made by Microsoft and others, and recommended that they be used more widely. The ISC Response The ISC strongly contested MITRE's conclusions, stating that MITRE's preference for open source stymies software innovation. Thebest way to promote innovation, according to the ISC, is to "ensure that customers -- both public and private -- have a broad range of choices in their software purchasing decisions." In particular, the ISC disagreed with the MITRE report's findings that open source products allow "early and rapid closure of security holes ... [which is] generally impractical in closed source products." In arguing against this finding, the ISC stated that "no single development mode inherently produces safer, more secure software." GPL Issues The ISC report also found fault with MITRE's conclusions about the General Public License (GPL). The GPL , which is used by some programmers in the open source community, requires developers to make their source code publicly available if they modify a program already licensed under the GPL. The ISC noted that, if there were a government policy requiring all software purchases to be licensed under the GPL, it would entail significant loss for commercial software developers. These developers "expend significant resources walling off their proprietary intellectual property," the report said. ISC pointed to MITRE's findings that more than 50 percent of the DoD's open source products are GPL-based, and that if proprietary developers were required to use the GPL, it would "foreclose proprietary companies ... from further developing and commercializing the results." . The Initiative for Software Choice advises the DoD to balance proprietary and open source software rather than favoring one.. Open Source Software, Proprietary Software, Government Policy, Software Innovation, DoD Procurement. . LinuxSecurity.com Team

Calendar%202 Dec 02, 2002 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200