The five most feared words in the IT support person’s vocabulary are “This. Page. Can’t. Be. Displayed.” And yet, the growth of Service Oriented Architecture (SOA) based enterprises in the past eight years means that these dreaded words show up more and more, as services from different developers and vendors are consumed by larger, up stream platforms and and integrated to provide new capabilities. In this kind of environment, “This Page Can’t Be Displayed” is a cry for help: the first indication of a problem. For enterprise support personnel, that message is often the first step in a long journey complete with Sherlock Holmes-style sleuthing to try to find which service along an orchestrated chain is the bad actor. And, unfortunately, when an application is being attacked or gets hacked, support personnel may not even have an error message to go on. In both cases, the major roadblock for support and incident response staff is that application developers or development […]
Tag: standards
New ZigBee IoT Standard To Replace Six Others
One of the main players in the Internet of Things communications space, The ZigBee Alliance, announced that it has merged six existing standards covering everything from building automation to healthcare to form a single standard:ZigBee 3.0. The announcement, last week, comes as ZigBee looks to compete with other emerging IoT standards. It says ZigBee 3.0 will provide interoperability among a wide range of smart devices that communicate based on its technology, laying the ground work for an expansion of IoT technologies. The new standard is being tested. According to the Alliance, the initial release of ZigBee 3.0 includes ZigBee Home Automation, ZigBee Light Link, ZigBee Building Automation, ZigBee Retail Services, ZigBee Health Care, and ZigBee Telecommunication services. The switch will impact tens of millions of devices already using ZigBee standards. However, the transition to ZigBee 3.0 will be gradual, as devices designed to use some of its constituent standards eventually transition to the unified […]
Strategies for Securing Agile Development: An Online Conversation
There’s no question that agile development methods, which emphasize collaboration and shorter, iterative development cycles, are ascendant. Many factors contribute to agile’s growing popularity, from constrained budgets to increased user demands for features and accountability. Though traditionally associated with small and nimble software and services startups, agile methodology has been embraced by organizations across industry verticals – many (like John Deere) whose name doesn’t scream “app store” or “Silicon Valley Startup.” But if agile is here to stay, a nagging question is how to pivot to agile’s fast-paced and iterative release schedules without skimping on important areas like code security. After all, the conventional wisdom is that security slows things down: imposing time- and labor intensive code audits and testing on the otherwise results-driven development cycle. Fortunately, agile and secure development aren’t mutually exclusive. Tomorrow (Thursday), the Security Ledger and Veracode will collaborate on a Hangout and discussion of how to build, automate and deliver secure software using the agile […]
Thread Gets Boost from Freescale Beta Program | EDN
We covered the announcement of Thread, a proposed IoT communications standard back in July. The question for Thread, as with competing IoT standards like Open Internet Connect and The AllSeen Alliance, is who will adopt it. Needless to say: without the embrace of software and device makers, even the best standard will wither on the vine. Now its seems like Thread is getting a boost from Freescale Semiconductor. That company last week announced a beta program that will give developers access to its own implementation of the Thread draft specification. As this report over at EDN Newtork notes, Freescale said at the Electronica 2014 conference that it is offering Thread-compliant versions of its Kinetis W series of wireless microcontrollers. The move is designed to encourage companies to create Thread-enabled products based on Freescale’s Kinetis platform. Freescale’s Kinetis family of devices are designed to enable connections between devices for home automation, healthcare, smart energy […]
Cyber insurance: Only fools rush in | ITworld
Cyber incidents these days tend to follow a familiar pattern: law enforcement is contacted and will begin criminal investigations. Cyber forensic investigators are hired to piece together what happened and security consultants will analyze and remove the malware from any affected systems. Finally: customers who were affected are notified and – typically -offered free credit monitoring services. All of these services come at a cost, of course, as does the business disruption that results. Current cyber insurance policies are structured to recover some or most of those costs. Now companies – from the Fortune 10 on down – are looking to hedge their online risks with various kinds of business insurance. That demand, in turn, is fueling a rapid expansion of the cyber insurance industry that was little more than a niche offering five years ago. But insurance industry experts and corporate security professionals offer words of advice for companies that think they […]