Data protection
Many UK computing graduates get no tuition on software security

UK computing students 'clueless' on security

Report points to lack of education at the most basic level

Written by Ian Williams, vnunet.com

UK computing students are receiving almost no education on how to incorporate security functionality when designing and developing new software applications, according to a damning new report.

The government-funded Cyber Security Knowledge Transfer Network (CSKTN) scrutinised open source web material from 75 UK universities.

The results suggest that just 20 per cent of UK computing graduates get no more than five hours' tuition on software security, and many get no tuition at all.

Advertisement

"Frankly I was surprised by how low the figures were," said Bill Whyte, an independent security consultant and author of the report.

"Today's computing market is a complex chain of software activities and is as vulnerable as its weakest link. The study is clear: security issues stem from the beginning of the chain.

"We need to get a much greater percentage of security-literate graduates out there or the number of otherwise avoidable financial losses will grow."

However, CSKTN director Nigel Jones believes that there is a much deeper issue in that software development does not feature strongly enough on the UK's list of IT security priorities.

The organisation hopes to drive home the message that better consideration of secure coding and software development could help reduce the number of software flaws which can be exploited by attackers.

Such an initiative could also reduce the number of security vulnerabilities in software caused by poor design, such as weak authentication.

"The cost associated with security breaches and investment in information security could both be mitigated if software was developed with fewer security flaws and vulnerabilities," explained Jones.

"The bottom line is that, if we want to solve the problems, we need to start by fixing the root cause."

Jones added that perhaps the biggest problem is that awareness of security during software design is very limited.

"A recent report on UK information security breaches by the Department of Business, Enterprise and Regulatory Reform and PricewaterhouseCoopers contained not a single reference to secure software development in any of its 32 pages," he said.

John Harrison, chairman of the CSKTN special interest group on secure software development, believes that the government has a pivotal role to play in insisting on high security standards when buying applications from third-party developers.

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive CD Rom 10
All 26 issues of Computeractive from 2007 on one CD-Rom.

Ultimate Guide to PC Troubleshooting
Everything you need to know to solve your PC problems.

Create your own calendars softwareCreate your own Calendars
The fun and easy way to create your own calendars!

Computeractive - Issue 280Computeractive Back Issues
Missed an issue? Click here to find a back issue

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

Vista chess frustrations

03 Dec 2008I would have to admit that I'm no great chess player, but it seems that Vista makes up for any deficiencies in...

Download Junkie

Download Junkie

Your daily dose of download discussion

Optimise your computer for a particular task with PowerUp

03 Dec 2008Tweaking the performance of your Windows operating system may sound relatively easy, but if you don't really know what you're doing, it...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2008. Incisive Media Limited, Haymarket House,
28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503

Search computeractive.co.uk