Home > Ask the Security Experts > Expert Archive: Security Management Questions & Answers > Are independent researchers out for fame?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Are independent researchers out for fame?

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 21 August 2008
As a security manager for a large organization, I try to keep an eye on vulnerability disclosures from all sources -- news, blogs, research groups, vendors, etc. However, X-Force recently released a report that seemed to cast a shadow on independent researchers. If those guys are out for fame, as the report suggests, should we pay less attention to them?

>
Security professionals are paid to protect the private data and intellectual property of their organizations. That means it's necessary to evaluate every credible threat and decide if/when to take action.

Infosec pros don't have the luxury of playing favorites in terms of where credible threat information comes from, so I think it would be a bad idea to take any legitimate threat information less seriously.

That being said, clearly there are a number of security researchers out there that are more interested in their own celebrity status than helping out the industry, but those individuals are few and far between. Most of the researchers I know actually lose money by doing their research -- given the opportunity cost of poking at applications and network infrastructure -- as opposed to billing large customers a lot of money to tell them where they are exposed.

The X-Force survey was arbitrary at best. It used a criticality metric that is subjective and probably not relevant to most organizations. Of course, they have to keep their own research teams motivated, so it's clear why they would beat the drum for that kind of survey.

A lot of these rumblings about independent security researchers are irrelevant. The sooner a potential security issue is exposed, the better. If that information comes from a big company, that's great. If it comes from an independent researcher, that's good, too.

Keep in mind the bad guys don't play favorites. Neither should anyone else.

More information:


BROWSE BY TAG
Expert Archive: Security Management,   Enterprise Risk Management: Metrics and Assessments,   Information Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Expert Archive: Security Management
What is the GISP certification and how does it compare to the CISSP certification?
Using a QSA to write up a PCI DSS report on compliance (ROC)
How can gap analysis be applied to the security SDLC?
Comparing cheap security products and appliances to costly appliances
What are some tips on protecting my security budget in a poor economy?
What value do research firms provide to their subscribing enterprises?
What certificate offers the best ROI for an IT project manager?
Is insider activity or outsider activity a bigger enterprise threat?
How does information security prevent fraud in the enterprise?
Differences between an SAS 70 data center and a Tier III data center

Enterprise Risk Management: Metrics and Assessments
How to justify information security spending on cloud computing
Layoffs prompt insider threat fears, cybersecurity survey finds
How to avoid Internet liability lawsuits
Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
Bernie Rominski: Communicate Effectively with Management about Risk
Best Policy and Risk Management Products
Monitoring program data and internal controls for risk management
Risk management strategy for an information technology solution provider
Align your data protection efforts with GRC
The basics of enterprise GRC project management
Enterprise Risk Management: Metrics and Assessments Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts