Read up on the latest ideas and technologies from companies that sell hardware, software and services. Wireless LANs: Is my enterprise at risk?
Best Practice in Building an Integrated Information Management Strategy
CRM your salespeople will love
Email Archiving Technical Overview
Taking On Demand CRM Integration to the Next Level
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Revolutionising Back-up and Recovery
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
FRAMINGHAM (03/03/2000) - Japan's defense agency pulled the plug this week on a new network linking army bases, after discovering that the software was written by members of a doomsday cult. Scary, huh? It gets scarier: Five contract software companies run by members of the Aum Shinri Kyo ("supreme truth") cult also wrote code for government agencies overseeing education, construction, the post office and the telephone system - as well as for hundreds of corporate customers.
Maybe that Aum name sounds familiar. In 1995, Aum members released nerve gas in a Tokyo subway, killing 12 people and injuring thousands more. Japanese authorities are afraid Aum programmers installed back doors or sabotage triggers in the contract software. The cult itself now says it has cleaned up its act and renounced law-breaking. But why take that chance?
Japan isn't alone in worrying about contractors. In the U.S., the Federal Aviation Administration is running after-the-fact background checks on dozens of Chinese, Pakistani, Ukrainian, British and Ethiopian programmers who worked on the FAA's Y2k fixes. None of the foreign programmers have been accused of doing anything wrong - but, the agency figures, why take a chance?
And after the latest round of Web site attacks, some security gurus are saying that no one should hire reformed hackers for any IT work. We shouldn't take the chance, they say, when we know these kids have histories of break-ins, back doors and bad behavior.
Are things really that bad? Yes. The more we outsource, the less we know about the people who'll get elbow-deep into our systems. They could be terrorists, industrial spies or crackers who plan to shut us down, steal our secrets or use our computers to launch attacks. We just don't know.
Is there an answer? Yeah, but no one's going to like it much. We're outsourcing that work to save time and money. And the only way to protect ourselves is to spend - what else? - time and money.
We'll have to spend time checking code we get from contractors. And grilling ASPs on their security standards and procedures. And drilling down to make sure subcontractors get the same hard stares as the big names who got the original contracts.
We may have to spend money on serious background checks for some contract workers - remember, real bad guys will lie on résumés and arrange for fake references.
We'll probably have to pay for insurance to make sure any losses due to dirty dealing are covered. Not prime-contractor performance bonds, but real insurance - if something goes horribly wrong, we want to make sure somebody with deep pockets will pay to make it right.
Yes, we should have been doing this all along. Some IT shops have been. But most of us slid into outsourcing a little at a time: A quick fix when a project went awry. Some extra help launching a Web store. Picking up an ongoing deal when we took over work the marketing or human resources department started.
Now we're outsourcing all kinds of things - systems development, applications, network management, maybe even the help desk. And we haven't got the oversight procedures in place to make sure the people who do our work for us are who we think and are doing what we want - and not walking away with any proprietary knowledge.
And now the brass will scream when we ask for a bigger budget to look over those outsourcers' shoulders. When they do, we can point out that farming out IT work is still cheaper than doing it all ourselves. We can suggest that they just think of it as doing due diligence. And we can remind them that the bad guys aren't a theory - as we know from places like Japan, they're very, very real.
Why take the chance?
Hayes, Computerworld's staff columnist, has covered IT for more than 20 years.
His e-mail address is frank_hayes@computerworld.com.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Strategies for Eliminating .PST Files
Join industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.










