Security- How do you know?
What is your top consideration in evaluating a product's security?
Number of reported vulnerabilities
Scale of informal review
Product reputation
Formal evaluation against a standard
Attractiveness of the person pitching the product
Other (please explain)
In addition to answering, please provide your level of purchasing power (or just "personal"), level of education and any related certifications you may hold.
I think this information will be very enlightening for discussing security with the widest range of people, by determining patterns (if any exist in who responds to what)
cheers,
catch
Other (Cutomization and R & D)
Other
1) Cutomization
Formal evaluation against a standard - In addition to the standards in the product, being involved in a VERY LARGE CORPORATION before, I want to reflect something about customization.
Setting up a reliable and secured system to be implemented in the production (I just want to emphasize the security aspect of the product), in order to consider the product's security (in an operational stand-point), I could say that CUSTOMIZATION is to be considered. Answering the question like "HOW WILL THE PRODUCT BE DEPENDABLE AND PROVIDE A SMOOTH, RELIABLE AND SECURED PROCESS ON THE EXISTING SYSTEM ESPECIALLY IF THERE IS A NEED FOR PRODUCT ADJUSTMENT RATHER THAN CHANGE THE ENTIRE EXISTING SYSTEM?" is the main concern of the company. Don't take this idea as far from the SECURITY ASPECT, since the meaning of a secured product includes it's reliability from start to end process. If the company's requirement from the product cannot be addressed (on certain standards), customization takes place. Products should be flexible enough to serve its purpose in a multi-process system. Taking consideration, for example, Accounting System, although it has standard processes, CUSTOMIZATON can be considered in a critical area where the SECURITY itself is involved. To dig deeper, we go to the payment process involved in the product. It should carefully be analyzed if such product could serve critical payment process in which existing manual system is doing. Automating payment system should carefully take in consideration the various means associated with the existing procedures. If the standard process of the product cannot serve the existing process of the client, a CUSTOMIZED version should be formulated or presented.
Another more relevant example is setting up corporate antivirus system to control Company E-Mails. With the same company, way back during the time that FULL network is just starting to be implemented, one problem that the Information System Dept. had faced is to choose an Enterprise AV that would addressed the issues involved in the network. Company E-Mail system needs to be controlled since during that time (1999), rise of VIRUS spreading via E-Mail were iminent on that company. The IS Dep't. had to be careful in evaluating AV product that will suit the fresh E-Mail system. Consulting firms especializing in this field had been most helpful and had recommended the customize and flexible type of AV product.
In a Larger Organization (WHERE PURCHASING POWER IS NOT A PROBLEM - BUDGET IS GOOD :D ), it is essenstial to consider CUSTOMIZATION and FLEXIBILITY of the product. As long as the product will address the issues involved, it could be consider a good secure point in the Organization entire process.
2) R & D (Research and Development)
As long as the product has continuous R & D, say presenting expandability and scalability, especially in the SECURITY and SOPHISTICATION (it goes hand-in-hand, right?), it will be good bet on it.
Yo!