Home > Security News > 2002 predictions from expert Stephen Mencik
Security News:
EMAIL THIS

2002 predictions from expert Stephen Mencik

By Stephen Mencik
14 Dec 2001 | SearchSecurity

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



We asked security experts to give us their industry predictions for the New Year. Here's what Stephen Mencik had to say.

I've never had a very good crystal ball, but I'll give you my thoughts.

  • 2002 will (again) be billed as the year for public key infrastructure (PKI). Again, PKI will not be widely implemented.

  • There will be greater emphasis on using biometrics for identification and authentication. While this is a good thing and will likely have success in the long run, I don't think the user community at large is ready yet for wide-scale biometric implementations.

  • There will continue to be many virus and worm attacks, and many people and companies will be affected due to continued poor operating practices (not stopping certain types of e-mail attachments, not updating antivirus signatures, etc.).

  • Web site defacements and other Web server attacks will continue. Many people still do not keep up with security patches and other advisories. Even those that do can still get hit. Remember that the attacker's job is easier than the defender. The attacker only needs to find one hole, the defender needs to find (and fix) them all.

  • National Security Telecommunications and Information Systems Security Policy No. 11, the National Information Assurance Acquisition Policy, requires that after July 1, 2002, the acquisition of all Commercial Off-the-Shelf Information Assurance (IA) and IA-enabled IT products be limited to those evaluated in accordance with either the Common Criteria, National Information Assurance Partnership Evaluation Program or the Federal Information Processing Standards' validation program. Despite this policy, many waivers will be granted allowing non-evaluated products to be acquired, rendering this policy moot, much as the policy for "C2 by '92" became a non-issue.


    Stephen Mencik
    Stephen is a Senior Infosec Engineer for ACS Defense, Inc. He has worked in computer and network security since 1981, and was a charter member of the DoD Computer Security Center. Stephen answers your network and infrastructure security questions via searchSecurity's Ask the Expert feature.

    Do you agree or disagree with Stephen's predictions? Share your thoughts in our anonymous discussion forum.



    Tags: IndustryVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Industry
    Breach forces payroll service provider PayChoice to shut down again
    SSH key compromise shuts down Apache website
    Twitter, Facebook hit by denial-of-service attacks
    Is a partnership certification worth the money? Part III -- security
    Experts weigh in on spyware's defining moment
    Presentation: Employee monitoring -- Balancing best practices and privacy
    Presentation: Security budgets -- Getting what you need
    Presentation: Understanding business requirements -- A blueprint for digital security
    Presentation: Staffing security positions -- How to choose the right personnel
    Organized fraud: Internet hackers conduct coordinated hacking attempts

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts