Computerworld
Frankly Speaking: Why Risk It?
Frank Hayes  03 March, 2000 12:01

FRAMINGHAM (03/03/2000) - Japan's defense agency pulled the plug this week on a new network linking army bases, after discovering that the software was written by members of a doomsday cult. Scary, huh? It gets scarier: Five contract software companies run by members of the Aum Shinri Kyo ("supreme truth") cult also wrote code for government agencies overseeing education, construction, the post office and the telephone system - as well as for hundreds of corporate customers.

Maybe that Aum name sounds familiar. In 1995, Aum members released nerve gas in a Tokyo subway, killing 12 people and injuring thousands more. Japanese authorities are afraid Aum programmers installed back doors or sabotage triggers in the contract software. The cult itself now says it has cleaned up its act and renounced law-breaking. But why take that chance?

Japan isn't alone in worrying about contractors. In the U.S., the Federal Aviation Administration is running after-the-fact background checks on dozens of Chinese, Pakistani, Ukrainian, British and Ethiopian programmers who worked on the FAA's Y2k fixes. None of the foreign programmers have been accused of doing anything wrong - but, the agency figures, why take a chance?

And after the latest round of Web site attacks, some security gurus are saying that no one should hire reformed hackers for any IT work. We shouldn't take the chance, they say, when we know these kids have histories of break-ins, back doors and bad behavior.

Are things really that bad? Yes. The more we outsource, the less we know about the people who'll get elbow-deep into our systems. They could be terrorists, industrial spies or crackers who plan to shut us down, steal our secrets or use our computers to launch attacks. We just don't know.

Is there an answer? Yeah, but no one's going to like it much. We're outsourcing that work to save time and money. And the only way to protect ourselves is to spend - what else? - time and money.

We'll have to spend time checking code we get from contractors. And grilling ASPs on their security standards and procedures. And drilling down to make sure subcontractors get the same hard stares as the big names who got the original contracts.

We may have to spend money on serious background checks for some contract workers - remember, real bad guys will lie on résumés and arrange for fake references.

We'll probably have to pay for insurance to make sure any losses due to dirty dealing are covered. Not prime-contractor performance bonds, but real insurance - if something goes horribly wrong, we want to make sure somebody with deep pockets will pay to make it right.

Yes, we should have been doing this all along. Some IT shops have been. But most of us slid into outsourcing a little at a time: A quick fix when a project went awry. Some extra help launching a Web store. Picking up an ongoing deal when we took over work the marketing or human resources department started.

Now we're outsourcing all kinds of things - systems development, applications, network management, maybe even the help desk. And we haven't got the oversight procedures in place to make sure the people who do our work for us are who we think and are doing what we want - and not walking away with any proprietary knowledge.

And now the brass will scream when we ask for a bigger budget to look over those outsourcers' shoulders. When they do, we can point out that farming out IT work is still cheaper than doing it all ourselves. We can suggest that they just think of it as doing due diligence. And we can remind them that the bad guys aren't a theory - as we know from places like Japan, they're very, very real.

Why take the chance?

Hayes, Computerworld's staff columnist, has covered IT for more than 20 years.

His e-mail address is frank_hayes@computerworld.com.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Best Practices in Lifecycle Management

This white paper compares solutions from KACE, Altiris, LANDesk, and Microsoft. Read on for best practices, functional solution comparisons and cost comparisons. Determine overall value easily and quickly.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.