IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 

 


Thu, Mar 13, 2008 12:18 EDT

Unintentional Betrayal of CIOs

Topic: Partner/Vendor Management

Current Rating: 5 Comments: 0

Currently, buying decisions for security solutions are heavily influenced by the reviews and certifications they receive that measure product quality and effectiveness. These ratings, published by independent third parties, are oftentimes used as a barometer for how CIOs make buying decisions and whether they decide to go with one product over another. What CIOs don’t realize however, is that the sources they have been depending on for these “valuable” second opinions, are using outdated and inaccurate testing methodologies, and therefore, providing a false sense of security.

The current testing methodologies utilized by reviewers and independent third parties to verify that a product meets certain requirements mainly takes into perspective a small portion of the vendor's protection model related to prevention capabilities for malicious code. Security products are being rated against their ability to catch known viruses via signature based defenses. In addition, these tests do not take into consideration the vendor's proactive capabilities, either through heuristics or behavioral-based technologies. Thus, current malware testing does not reflect the vendor's actual capabilities to protect their customers from the most relevant security threats.

The main problem with this approach is that signature-based defenses are failing to protect companies against the onslaught of new threats that are classified by malware technicians each day by the thousands. In fact, the average infection rate in systems with up-to-date protection is 72 percent according to a study conducted by PandaLabs (http://research.pandasecurity.com/archive/Think-you_2700_re-protected_3F00_-Think-again.aspx).

Using these inaccurate testing methodologies, product reviewers are not looking at the entire picture and are only basing their ratings on a portion of the entire product’s detection capability. If the reviews are not all-encompassing, conducted inconclusively and/or neglect to factor in all aspects of malware detection and prevention, the ratings will be skewed.

So what is the anti-malware industry doing about this issue?

The industry is addressing this problem through the formation of a standards group known as the Anti-Malware Testing Standards Organization—or AMTSO—in which Panda Security is a founding member. The objective of the AMTSO is to promote standards and best practices for correctly testing and evaluating the effectiveness of anti-malware solutions on the market. A vast number of other vendors including Microsoft, IBM, McAfee and Symantec are also a part of this group because they all recognize that significant improvements need to be made in the review process.

With the formation of the AMTSO, we hope that reviewers and independent third parties adopt the best practices developed for testing and evaluating anti-malware solutions—taking into consideration all parts of a vendor's protection model and not just focusing on signature-based detection as the sole driver for product quality.

By adopting these standards, reviews will become more encompassing of the entire product’s security capability and will offer a more authentic performance rating. This will benefit CIOs in the long term as they will be purchasing products on the basis of actual protection capabilities and not a pre-conceived notion that users are protected by the signature module.

For more information on anti-malware testing standards and how you can stay abreast of emerging issues in information security, please visit: (http://www.takethepandachallenge.com/whitepapers.aspx)

Ryan Sherstobitoff,
Chief Corporate Evangelist, Panda Security

You do not have flash or javascript support.
Average (3 votes)
5
 
Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 90 of IT's most insightful thinkers.

advertisement

TOP USERS
UserPoints
1. laith al jazi12550
2. Akshay Upadhye7650
3. Chris Moore6750
4. abdhiraj6175
5. remi5525
UserPoints
6. Mark Cummuta4675
7. Brian Flora4575
8. Al Sacco4200
9. asengupta3750
10. reCareered3700
  PARTNERS       PODCASTS       WEBCASTS    
 

Enterprise Content Management: From Strategy to Solution

Enterprise content management (ECM) has become an important competence and infrastructural technology, particularly for large and medium-sized organizations. Hear about industry trends for ECM and why standardizing your ECM platform is so critical to your success during this roundtable discussion.

Sponsored by IBM  View This Webcast »

 

The CIO's Guide to Wireless in the Enterprise

This guide provides a basic overview and worksheet of mobile computing for those who are interested in evaluating a wireless enterprise solution.

Sponsored by Blackberry
  Read This White Paper »

 

The Universal Wireless Client

Learn how replacing multiple wireless clients with one Universal Wireless Client can cut support and help desk costs, increase end user satisfaction, improve security, and help implement Network Access Control.

Sponsored by Fiberlink  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

NAC launch from HP Procurve Podcast with Lippis Report, Part 1

ProCurve Networking by HP joins the Lippis Report to announce major product and organizational additions to their ProActive Defense strategy.  Read More »

 

Accenture's View on Web 2.0 and its impact on business

Publisher at CIO magazine, Bob Melk, talks to Accenture's Blair Jones about the emergence of Web 2.0...  Read More »

 

A Best-Practice Framework for Virtualization

This podcast offers insights and perspective on the various issues that relate to virtualization...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Forrester builds a case for the next generation information workplace.

As businesses seek new ways to enhance collaboration and improve productivity, the information workplace continues to evolve...  Read More »

 

Find out what Forrester says about mobile endpoint security and its management.

Mobility raises productivity. But IT departments are hard-pressed to protect mobile data and to manage security software, wireless clients and regulatory compliance for mobile workers...   Read More »

 

Get Forrester's take on simplifying mobility with the universal wireless client.

Mobile workers want to use all types of wireless networks: WiFi, 3G cellular networks, corporate WLANs and home wireless networks. But how can IT support...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Advice & Opinion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Reducing Data Center Costs with Data Deduplication: A TCO Analysis

TDWI Research report clears confusion about automating data governance

Learn about the software-based VoIP solution from Microsoft

Microsoft System Center - Designed For Big

Storage Efficiency: The Key to Green Storage Operation

Fuel the Responsive Enterprise Through Oracle Fusion Middleware

Balance Your Innovation and Efficiency Platforms for Competitive Advantage and Responsiveness

Oracle Real Application Testing with Oracle Database 11g

InfoWorld Test Center on Oracle Active Data Guard

Master Data Management: The Approach Determines the Results

The Power of Pervasive Business Intelligence

Reap the Benefits of Unified Communications

Controlling High Fraud Risk of International Transactions

Renowned Engineering Institution Chooses AMD Processor-Based Servers

How to Manage the Mobile Work Environment

Extending PCI Compliance to the Mobile Workforce

Solving Online Credit Fraud Using Device Reputation

Process Integration and Traceability through Requirements Management

Virtual Support Technology Delivers Quantifiable Gains in Productivity and Performance

Building Competitive Advantage with Next-Generation Wireless Infrastructure

Building an Online Customer Experience Competency

Skechers, an IBM Customer Case Study

What Is Innovation and What Role Do CIOs Have In It?

Configuration Assessment: Choosing the Right Solution

They Can't Steal What You Don't Have: Smart Security Choices for Mobile Workers

Speed, agility, flexibility - The HP BladeSystem c-Class

Cost-Effective Data Center 1U Server Solutions

Secure your virtual and physical environments with the same software

GET YOUR VoIP ONTM! Win 2 Years of Hosted VoIP from Cypress. $100,000 retail value. Enter today!

Standalone Server vs. Open Source Toolkits

Drive More Effective Business Processes with SOA

Oracle Database 11g: Real Application Testing & Manageability

InfoWorld Test Center on Oracle Real Application Testing

Oracle Database 11g: Advances in Compression, Real Application Testing and Data Guard

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

Conquering Information Management Challenges

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

The Universal Wireless Client: Simplify mobility and reduce the cost of supporting mobile workers

Strategic IT Financial Management - Achieve Higher Organizational Performance

Strategies for Asia-Pacific Expansion

Unified Communications: "More Than Just Talk"

Accelerating ITIL at the Service Desk

New research validates telepresence solutions.

The Gartner Magic Quadrant

How to Choose the Right ECM Platform

Optimizing Infrastructure Control

Effective Security with a Continuous Approach to ISO 27001 Compliance

Best Practices for Providing Secure and Cost-Effective Remote Access