ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Toolkit

Story: Vendors, not developers, to blame for poor code

  • Previous comment

Posted by: Arthur B. (Thursday 20 October 2005, 10:43 PM)

  • Reply

Indeed, liability should be introduced at the level where the most positive difference can be made.

Since the brass usually doesn't take orders from lower staffed personal, like developers, it's clear where responsibility (e.g.: liability) should be placed if you want things to change.

That said, just introducing liability for computer security related problems at only the IT vendor level isn't enough. There are more organizations involved in the process that leads to implemented, poorly secure(d), software at customers sites. Examples would be IT Solutions Providers, IT System Houses, outsourcing companies, etc..

If we want to introduce liability for poor secure(d) software then we need to take into account all the factors. We can't have years long court battles involving a vendor claiming that their software is secure as long as you implement and maintain it correctly while the implementor and maintainer tells a different story and the customer is sitting in the middle getting nowhere fast.

In short. When pointing fingers of blame make sure there are no grey areas for anyone to hide in beforehand. That means covering all the bases.

Point to keep in mind. There should be a balance between what some external IT company can be held liable for and the amount of revenue achieved from the customer in question.

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread