|
PowerTech Offers Open Source Security Policy
Published: April 4, 2006
by Dan Burger
Open source software is software that belongs to a community of developers who constantly suggest ways to improve it based on experiences, knowledge, and a good bit of trial and error. It improves because of the contributions of many who are familiar with the software and the objectives. The same idea is being applied to devising a security policy. PowerTech, a security software vendor, has presented its best ideas for a security policy and is hoping other security professionals will contribute insight and expertise as an open source project.
"We understand security compliance and recognize that many organizations just need a place to start," says Bruce Leader, PowerTech's president and CEO. He sees it as a valuable resource for organizations developing their own policies--one that can reduce the steps required when starting out from scratch. Leader says the open source format will allow others in the industry to contribute their insights and expertise "to make this the most comprehensive iSeries security policy available." In keeping with open source standards, PowerTech plans to incorporate the best of the submitted enhancements into future editions of the OS/400 policy document.
Regulatory compliance issues have put a spotlight on internal security procedures at organizations that come under the scrutiny of outside auditors. But the lessons learned under these circumstances also fit well within the companies not touched by regulation.
"Auditors and their requirements are constantly evolving and so are government regulations," says John Earl, PowerTech's vice president and CTO. "We often hear from our customers, that the first thing the auditor wants to see is their security policy. If they don't have one, they are already in the doghouse." Earl calls the existing document the first installment and a starting point that allows OS/400 professionals to get a jump on putting a first-class security policy in place.
The open source security policy is available for downloading. Those who have suggestions for enhancements and changes to the policy are encouraged to come forward with ideas and comments. PowerTech officials will protect the privacy of policy contributors if that corresponds with the individuals' wishes.
|