Home > Security News > Survey: Vista security skepticism swells
Security News:
EMAIL THIS

Survey: Vista security skepticism swells

By Bill Brenner, Senior News Writer
01 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

When Windows XP Service Pack 2 (SP2) was released nearly two years ago, most IT professionals said they were worried about compatibility problems and that they'd wait a while before deploying it in their enterprise.

The full release of Vista, the next big upgrade for Microsoft's operating system, isn't due out until early next year. A new survey though suggests Vista is already being viewed with skepticism similar to what was directed at SP2 in 2004.

According to a survey by Boca Raton, Fla.-based Amplitude Research conducted on behalf of Albuquerque, N.M.-based security firm VanDyke Software, more than half of respondents said they have no plans to deploy Vista when it comes out, despite all of the security improvements that Microsoft says will be baked into the operating system.

Amplitude culled the information after surveying 255 network and system administrators last month from a variety of industries. The enterprises also varied in size. Of those polled:

  • 10.98% are testing the limited beta version of Vista.
  • 19.21% are waiting until the public beta release to begin testing.
  • 25.49% are waiting until the official release to begin testing.
  • 5.09% have plans to deploy after successful completion of beta testing.
  • 20% will deploy after successful completion of testing of the official release.
  • 11.37% will deploy after Service Pack 1 for Vista is released.
  • 11.37% will deploy only on new PCs with Vista pre-installed.
  • 52.15% said they have no current plans to deploy Vista.

    Of those who do plan to test or deploy it, 58.33% said their primary interest in Vista is its "enhancements," while 30.12% cited "improved usability." Of those who have no plans to deploy Vista:

  • 36.84% said they can't justify the return on investment.
  • 36.84% said they feel more comfortable sticking with the current version of Windows.
  • 9.02% said there are no features in Vista to justify the upgrade.
  • 2.25% said they don't use Windows.
  • 1.5% said too many features have been dropped.
  • 13.53% listed "other" reasons.

    Are respondents skeptical over Microsoft's past security challenges? Not necessarily, said Amplitude Research CEO Stephen Birnkrant.

    For more information

    Vista delay not as dramatic for enterprises

    Microsoft says Vista security will drive adoption

    "I think it's just that it's a major change and IT administrators want to take it slowly," he said. "Some may also be looking at Vista's delayed release and reassessing their own plans in light of that delay."

    He noted that Vista's delay was announced around the time the survey was conducted. "I think that was a factor," he said.

    VanDyke Software also commissioned Amplitude Research to conduct a simultaneous, separate survey of 252 network and system administrators working in the computer hardware, software and telecommunications industries.

    "The findings suggest a high level of segmentation regarding adoption plans, with 67.04% of the 252 respondents indicating that they would deploy Vista," Birnkrant said. "Why the percentage of those planning to deploy Vista is higher in these sectors, I couldn't tell you."

    One factor in the overall response may be that IT professionals are reluctant to put all their security eggs in one basket. Vista has been touted as an upgrade with a number of built-in security features, but according to the survey, more than 90% of respondents said they prefer a mix of security tools. Specifically, only about 8% said they rely on a single-source vendor to assemble their arsenals of information-security tools, while 90.58% said they "mix-and-match" from multiple sources.

    But Birnkrant doubts those responses had anything to do with Vista. "I'm not convinced the security tools in Vista are the same tools people were thinking of when they answered the single-source security questions," he said.

    Tags: Windows Security: Alerts, Updates and Best PracticesConfiguration Management PlanningEnterprise Risk Management: Metrics and AssessmentsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Windows Security: Alerts, Updates and Best Practices
    Microsoft to address flaws in Windows, Office for Mac
    Microsoft fixes security update that breaks Internet Explorer
    What is the best database patch management process?
    Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
    Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
    Microsoft releases temporary fix for SMB2 zero-day vulnerability
    Microsoft issues SMB vulnerability advisory, patch pending
    Attackers target Microsoft IIS; new SMB flaw discovered
    Microsoft repairs Windows media, TCP/IP vulnerabilities
    Microsoft five critical updates won't include IIS

    Configuration Management Planning
    Integrated change management reduces security risks
    EMC adds configuration management with Configuresoft acquisition
    McAfee to acquire Solidcore Systems for whitelisting
    Product Review: Shavlik's NetChk Compliance
    Security services: Fiberlink's MaaS360 Mobility Platform
    CISSP Essentials training: Domain 10, Operations Security
    5 Steps for Developing Strong Change Management Program Best Practices
    Misconfiguration issues could have contributed to Hannaford breach
    Misconfigured networks create huge security risks
    Private sector should learn from government insecurity
    Configuration Management Planning Research

    Enterprise Risk Management: Metrics and Assessments
    How to avoid Internet liability lawsuits
    Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
    Bernie Rominski: Communicate Effectively with Management about Risk
    Best Policy and Risk Management Products
    Monitoring program data and internal controls for risk management
    Risk management strategy for an information technology solution provider
    Align your data protection efforts with GRC
    The basics of enterprise GRC project management
    RSA council addresses growing security risks in the cloud
    How to write a risk methodology that blends business, security needs
    Enterprise Risk Management: Metrics and Assessments Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    BotHunter  (SearchSecurity.com)
    principle of least privilege (POLP)  (SearchSecurity.com)
    security identifier  (SearchSecurity.com)
    trusted computing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts