Skip the navigation

Vendor-backed Lobbying Groups Cozy Up to DHS

Organizations' self-serving agendas raise concerns that security burden will fall to users

By Dan Verton
December 1, 2003 12:00 PM ET

Computerworld - WASHINGTON -- When the Department of Homeland Security convenes its National Cyber Security Summit in California on Wednesday, its stated aim will be to improve cooperation with the private sector. But the question is whether it's cooperating too closely with IT vendor special interests.
The DHS is hosting the event in collaboration with IT vendor organizations whose lobbying activities are coming under increased scrutiny for pushing an agenda that would place the burden of security on the government and users rather than on the vendors that sell the products.
Co-sponsoring the event, to be held in Santa Clara, are the Information Technology Association of America, the Business Software Alliance, the TechNet alliance of CEOs and the U.S. Chamber of Commerce. A Computerworld review of the public policy statements of these groups found nothing to indicate that they have ever taken a position that calls on IT vendors to improve the security and quality of their products.
Moreover, the vendor groups partnering with the DHS this week appear to share an agenda aimed at frustrating legislation that would require companies to conduct third-party security benchmarks and report the results each year in their annual reports . All of those organizations played a role in blocking a bill with such goals last month, according to officials involved in drafting the legislation who spoke on condition of anonymity.
While many industry executives spoke on the record about the role of vendor groups in shaping public policy, others said privately that they agreed with the general perception that such groups are pushing political agendas at the cost of improved security.
"ITAA and BSA continue to put forth resistance that seems based more on visceral than logical grounds," said the president of another industry consortium that regularly deals with these groups. "They continue to say that externally defined security requirements, either from the government or users, stifle innovation, which strikes me as a classic red herring."
Amit Yoran, director of the National Cyber Security Division at the DHS, said that in his interactions with the vendor groups co-sponsoring the summit, he has witnessed "a genuine interest and desire to improve the state of cybersecurity." And while the concern about vendor resistance to regulation is a valid one, Yoran said, vendors are for the most part "putting their money where their mouths are."
"Before advocating specific legislative initiatives, they want to have a good, clear understanding of the upside and the impact of that legislation with respect to its effect on industry," said Yoran. "We need



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs