Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The department of energy has done something unusual for a federal agency. It has become an example of excellent cyber-security practice. It has done this by pressuring Oracle to elevate security in its 9i database product--in the process, taking software out . . . . The department of energy has done something unusual for a federal agency. It has become an example of excellent cyber-security practice. It has done this by pressuring Oracle to elevate security in its 9i database product--in the process, taking software out of the shadows of "as is" licenses and putting it in the spotlight of a government procurement action. DOE's action could begin a process that improves the security of the technologies available to the public and private sectors alike. To win this open-ended deal, Oracle promised to deliver its database in a secure configuration and took responsibility for the security of the software going forward. Future patches must be delivered quickly and cannot create new problems or vulnerabilities if Oracle wants to continue getting paid. It's the kind of vendor commitment that every enterprise merits but that only the $59 billion IT buying power of the federal government can effect right now. The link for this article located at eWeek is no longer available. . The energy sector establishes a benchmark by insisting on advanced safety measures from Microsoft for fortified cloud infrastructure.. Database Protection, Cybersecurity Standards, Government Procurement, Vendor Accountability. . Anthony Pell
If civilian agencies join the national security community in limiting technology purchases to items that have gone through independent evaluation, it could spur vendors to submit more products for certification, officials testified today before a House subcommittee. . .. If civilian agencies join the national security community in limiting technology purchases to items that have gone through independent evaluation, it could spur vendors to submit more products for certification, officials testified today before a House subcommittee . The national security community and the Defense Department already require any product with a security component, from a firewall to an operating system, to go through an independent evaluation that includes the Common Criteria, a set of tests to make sure that security-related products actually perform the way a vendor states. As agencies come together to use the Common Criteria to craft protection profiles -- descriptions of security characteristics an agency would like for its IT components -- the number of certified products is increasing. The trend would move even faster if civilian agencies were to join in the demand, said Michael Fleming, chief of the Information Assurance Solutions Group in the National Security Agency's Information Assurance Directorate. The link for this article located at FCW is no longer available. . Government departments can enhance their technological credentials by integrating defense protocols, urging suppliers to meet standards.. Tech Certification, Procurement Standards, Common Criteria, IT Security, Vendor Compliance. . Anthony Pell
The Small Business Administration and the Defense Department last week took the first step toward completing the Business Partner Network for government contractors. SBA integrated its small business database, PRO-Net, with DOD's Central Contractor Registration system. . .. The Small Business Administration and the Defense Department last week took the first step toward completing the Business Partner Network for government contractors. SBA integrated its small business database, PRO-Net, with DOD's Central Contractor Registration system . PRO-Net serves as agencies' small-business procurement resource, and the CCR is the central repository of information about contractors doing business with DOD. Small businesses can now enter their information in both databases simultaneously. CCR will rely on PRO-Net as the authoritative source for vendors certified under SBA's small-business contracting programs, such as 8(a) and HUBZone for historically underutilized businesses. Eventually the CCR will become the Business Partner Network, a key part of the Office of Management and Budget's Integrated Acquisition Environment, an e-government project. The network will then serve as the single point of registration and validation for vendors. Agencies also will have to register with the network to make interagency transactions. The link for this article located at GCN is no longer available. . The Federal Trade Commission and Department of Health integrated systems to enhance the regulatory process for consumer safety measures.. Small Business Integration, Government Contractor Registration, SBA PRO-Net, DOD CCR, E-Government Procurement. . Anthony Pell
The Initiative for Software Choice, a software industry trade group whose members include Microsoft, Intel and Cisco, has advised the U.S. Department of Defense not to adhere to a policy that promotes open source software at the expense of proprietary software. . . . . The Initiative for Software Choice, a software industry trade group whose members include Microsoft, Intel and Cisco, has advised the U.S. Department of Defense not to adhere to a policy that promotes open source software at the expense of proprietary software. The group has issued a report arguing that the DoD's evaluation of software purchases should not be influenced by "a preconception that open source software is somehow inherently more secure." "ISC is against government policy that restricts procurement to any kind of software," ISC executive director Bob Kramer told NewsFactor. He noted that the group has no prejudice against any software, but that government procurement policies "should focus on obtaining the best software to solve the problem." The ISC Mission The Washington, D.C.-based ISC was founded in May. The group states it is "dedicated to the principle that governments should procure their software products on their merits rather than categorical preferences." Therefore, its goal is to "educate policymakers about the need to remain neutral about the governmental purchase of software." Toward that goal, the ISC recently issued a report that countered another report written by defense contractor MITRE. The MITRE report noted that open source software "plays a more critical role in the [DoD] than has generally been recognized," and that the DoD has 115 open source applications with 251 identified uses. It then concluded that open source products are a viable alternative to proprietary products made by Microsoft and others, and recommended that they be used more widely. The ISC Response The ISC strongly contested MITRE's conclusions, stating that MITRE's preference for open source stymies software innovation. Thebest way to promote innovation, according to the ISC, is to "ensure that customers -- both public and private -- have a broad range of choices in their software purchasing decisions." In particular, the ISC disagreed with the MITRE report's findings that open source products allow "early and rapid closure of security holes ... [which is] generally impractical in closed source products." In arguing against this finding, the ISC stated that "no single development mode inherently produces safer, more secure software." GPL Issues The ISC report also found fault with MITRE's conclusions about the General Public License (GPL). The GPL , which is used by some programmers in the open source community, requires developers to make their source code publicly available if they modify a program already licensed under the GPL. The ISC noted that, if there were a government policy requiring all software purchases to be licensed under the GPL, it would entail significant loss for commercial software developers. These developers "expend significant resources walling off their proprietary intellectual property," the report said. ISC pointed to MITRE's findings that more than 50 percent of the DoD's open source products are GPL-based, and that if proprietary developers were required to use the GPL, it would "foreclose proprietary companies ... from further developing and commercializing the results." . The Initiative for Software Choice advises the DoD to balance proprietary and open source software rather than favoring one.. Open Source Software, Proprietary Software, Government Policy, Software Innovation, DoD Procurement. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.