<?xml version="1.0" encoding="utf-8"?><rss version="2.0">
<channel><title><![CDATA[Compliance Focus - Comments for blog: Between a rock and a hard place]]></title><link>http://www.compliancefocus.com</link><description /><language>en-us</language><copyright><![CDATA[http://www.compliancefocus.com]]></copyright><generator>N/A</generator><webMaster>jim@compliancefocus.com</webMaster><lastBuildDate>Tue, 07 Sep 2010 17:23:40 EDT</lastBuildDate><ttl>20</ttl><item><title><![CDATA[Comment #1]]></title><link>http://www.compliancefocus.com/blogs/22/Between-a-rock-and-a-hard-place.html#Comment3</link><description><![CDATA[While bad software design and QA certainly contribute and enable breaches, I'm not sure that the ability to sue software manufacturers would do much to address either the quality of software or the losses incurred from breaches.
Verizon Business RISK Team “2008 Data Breach Investigations Report” reports these numbers:

Attacks -
from outside the organization: 73%
implicating business partners: 39%
from internal sources: 18%

Median number of records compromised -
from external attacks: 30000
from partner attacks: 187500
from internal threats: 375000

Internal attacks by IT admin: 50%

My takeaway from these numbers is that while software flaws and incorrect configuration may enable attacks, the most direct damage is a result of mismanaged trust, in partners and people inside the company - half of which are IT admins.

Perhaps the lesson that companies should learn is that their relationship with employees and partners directly effects their security posture and managing those trust relationships should be a priority.

Or just figure out how to get software manufacturers to share the pain.<br/><br/>
(Comment posted by Joseph Webster at 12:37 pm, Wed 17th Sep 2008)]]></description><author>no@spam.com (Joseph Webster)</author><pubDate><![CDATA[Wed, 17 Sep 2008 12:37:52 EDT]]></pubDate><guid isPermaLink="true">http://www.compliancefocus.com/blogs/22/Between-a-rock-and-a-hard-place.html#Comment3</guid></item></channel></rss>