About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Data protection
Many UK computing graduates get no tuition on software security
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

UK computing students 'clueless' on security

Report points to lack of education at the most basic level

Ian Williams, vnunet.com 13 May 2008
ADVERTISEMENT

UK computing students are receiving almost no education on how to incorporate security functionality when designing and developing new software applications, according to a damning new report.

The government-funded Cyber Security Knowledge Transfer Network (CSKTN) scrutinised open source web material from 75 UK universities.

The results suggest that just 20 per cent of UK computing graduates get no more than five hours' tuition on software security, and many get no tuition at all.

"Frankly I was surprised by how low the figures were," said Bill Whyte, an independent security consultant and author of the report.

"Today's computing market is a complex chain of software activities and is as vulnerable as its weakest link. The study is clear: security issues stem from the beginning of the chain.

"We need to get a much greater percentage of security-literate graduates out there or the number of otherwise avoidable financial losses will grow."

However, CSKTN director Nigel Jones believes that there is a much deeper issue in that software development does not feature strongly enough on the UK's list of IT security priorities.

The organisation hopes to drive home the message that better consideration of secure coding and software development could help reduce the number of software flaws which can be exploited by attackers.

Such an initiative could also reduce the number of security vulnerabilities in software caused by poor design, such as weak authentication.

"The cost associated with security breaches and investment in information security could both be mitigated if software was developed with fewer security flaws and vulnerabilities," explained Jones.

"The bottom line is that, if we want to solve the problems, we need to start by fixing the root cause."

Jones added that perhaps the biggest problem is that awareness of security during software design is very limited.

"A recent report on UK information security breaches by the Department of Business, Enterprise and Regulatory Reform and PricewaterhouseCoopers contained not a single reference to secure software development in any of its 32 pages," he said.

John Harrison, chairman of the CSKTN special interest group on secure software development, believes that the government has a pivotal role to play in insisting on high security standards when buying applications from third-party developers.

See also:

Windows VistaMalware cracking Vista defences, claims anti-malware vendor  12 May 2008
Richard ThomasInformation Commissioner's Office gets tough  12 May 2008
MicrosoftGartner welcomes assurances that legal agencies cannot access Microsoft code  09 May 2008

All Developer
Tags: Government, Secure-software, Security, Skills, Software

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Server Support Analyst (Citrix skills required) - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & ... more >
Berkshire, Reading, United Kingdom | Foster Wheeler
Microsoft Application Support Specialist - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & LNG, refining, ... more >
Solihull, United Kingdom | Enzen Global Limited
Business Analyst - £30,000 - £35000 - Solihull We are in need of a Business Analyst with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
United Kingdom | University of east anglia
WEB DEVELOPER £22,332 to £27,466 per annum (Grade 6), with agreed progression to £28,290 to £33,780 (Grade 7). Pay award pending from October 2008. We are looking for an experienced Web Developer to join a ... more >
More job opportunities
ADVERTISEMENT