HomeSecuritySoftware: Organizations' awareness of vulnerabilities is lacking

Software: Organizations' awareness of vulnerabilities is lacking

Over the years, the need for security has become clearly essential. Those who are computer or Internet and enjoy the unlimited possibilities that are provided to them daily must also be aware of their imperfections. Software vulnerabilities are what create many of the problems, but also the need for repair.

Software

We must not forget, of course, that like everything, software was created by people and it is expected to have errors. It is simply that in cases where these errors burden critical systems, it is mandatory to address them immediately. The various defense mechanisms that have been created over the years, such as WAFs (Web Application Firewalls), are very helpful but do not fix everything that is needed. Some errors need to be fixed.

Both the private and public sectors are often at risk and subsequently affected. Now, the public sector and the government are using software that could potentially harm them. That's why the United States Department of Homeland Security (DHS) has issued guidance for US government agencies. These fixes are very important.

Of course, it is a fact that there is a relative incompetence on the part of organizations in terms of repairing software vulnerabilities. Proof of this is that for serious vulnerabilities, the average repair time exceeds one month. The time it takes hackers to access a vulnerable software? Sometimes a few hours are enough.

Sometimes the solutions used are not appropriate. Other times, there are not enough human resources and the priorities that are set are not what they should be. As a result, many departments operate without staff. The work to find a solution is usually done piecemeal, which means that systems remain unattended for days or weeks until the next cycle of testing and development.

The Ministry's new instructions call for reducing the days needed for repair to 15 calendar days and 30 days for implementing corrections. In addition, the Ministry will contact the departments within 15 days and if the change has not been made, it will await explanations.

However, simply reducing the time is not enough to protect an organization's systems from attack. Even organizations that follow the DHS mandate can be vulnerable to attack for up to 15 calendar days, as that is enough time for an attacker to discover and exploit a software vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS