5 ms·
> In Slavitt's defense, data security may not have been an explicit feature of QSSI's federal contract Coming from the construction industry, there isn't a con
by eigenvector 13y ago
> In Slavitt's defense, data security may not have been an explicit feature of QSSI's federal contract
Coming from the construction industry, there isn't a contractor in the world that cares about things which aren't in the contract. Implementing features which the client has not asked for, in the design-bid-build world of public-sector contracting, just means you will lose the bid to a lower bidder who won't do those extras.
- gohrt 13y agoRight. A solution is for the government to develop a series of security standards that cover a wide range of IT projects, and each project should declare that "implementation must conform to Security Level X, Category Y"
- dragonwriter 13y ago> A solution is for the government to develop a series of security standards that cover a wide range of IT projects, and each project should declare that "implementation must conform to Security Level X, Category Y" Well, you'd think so, which is why that's essentially already mandated: http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002 http://en.wikipedia.org/wiki/Federal_Information_Security_Ma... http://en.wikipedia.org/wiki/Federal_Information_Processing_Standards http://en.wikipedia.org/wiki/Federal_Information_Processing_...
- smackfu 13y agoAnd if you go beyond the contract, and stuff doesn't work, you get blamed and have to eat the cost of fixing it.
- growupkids 13y agoWhich is also true in government contracting. What's odd is that security requirements are mandated by law, FISMA, so the government is supposed to require that systems meet the FISMA requirements. You shouldn't be able to get an ATO without it, unless the management of that agency "accepts the risks" (SES levels only, gS personnel can't do this) and waives the vulnerabilities. So if I had to guess, if they didn't protect the data then it's likely those controls were notin place everyone knew they were not and the agency heads said it was ok. All fed systems get tested, and the system certifier is supposed to be an impartial reporter of the facts (these are the vulns, missing controls, risks, etc. and they are almost always impartial). They report those to the DAA along with a recommendation to approve or not approve the system to operate. Given how important this system was, I highly doubt anyone would not have issued the ATO no matter what vulns it had. And that's not to pick on this system, sadly slap dash rush ATOs happen far too often in the USG. If you spend a ton of time and money on a system, execs in the USG have their careers on the line to show that wasn't wasted and since they don't understand security it all seems like science fiction to them. They almost always ATO the system. And why not, no USG exec has ever been fired for having a poorly protected system broken into.
- dragonwriter 13y agoeigenvector: Implementing features which the client has not asked for, in the design-bid-build world of public-sector contracting, just means you will lose the bid to a lower bidder who won't do those extras. growupkids: Which is also true in government contracting. "Public-sector" = "government".
- greenyoda 13y ago"Coming from the construction industry, there isn't a contractor in the world that cares about things which aren't in the contract." In the construction industry, a contract might not explicitly say that the building has to comply with local building, fire and electrical codes - that's taken as a given. To construct a web site that deals with sensitive information without taking security into account is like building a skyscraper with no fire exits - not something that any honest or competent builder would do.
- thezilch 13y agoNot "would do" but "could do;" you can't build, honest and competent or not, without local code-compliance. Perhaps the same should be true for the web; perhaps there should be damages for poor security; government or not.
- dragonwriter 13y ago> Not "would do" but "could do;" you can't build, honest and competent or not, without local code-compliance. You can, and people do, and they are cited for it when caught. Likewise, there are mandatory standards for Federal IT systems, particularly in the area of security.
- lmkg 13y agoYes, but those are actual codes. In fact, that's why they're codes. Contractors won't do more than they're legally required to (nor should they be expected to), so safety features were made legal requirements. Relying on the honesty or competency of your contractors go above & beyond their requirements is an inefficient and unsustainable solution in a free market. This is a clear case of Moral Hazard: In the same way that bad money drives out good, corner-cutting organizations out-compete honest ones.
- benmanns 13y agoWhat about reputation? I regularly do more than the legal minimum for my clients and there are companies who do the same for me. Meeting the legal minimums only makes sense for commodities, e.g. this salt is 99.5% pure. This software is 99.5% "secure"? This software is 99.5% "complete"?
- nraynaud 13y agoactually security is not a feature, but a constraint. It doesn't bring the user anything, but it absence would be a problem for secondary reasons (that might be important in the grand scheme of things). Imagine a bank (well just an account), on the functional level, you just need to deposit and withdraw money. The fact that they have to secure it is a huge constraint, but at the functional level we're not far from a trash can, a parking lot or a gas tank.