Security News South Africa

Study: OSS communities are often slackers in security

Enterprises using certain kinds of open source software may be exposing themselves to serious security risks, according to a study from Fortify Software. The study, which focused primarily on non-commercially supported OSS, found many packages have no ground rules for reporting bugs and do not adequately inform users about how to use the applications safely.

The most widely used open source software packages for the enterprise are exposing users to significant and unnecessary business risks, according to an open source security study from security firm Fortify Software.

The study, released Monday, concludes that open source software (OSS) development communities have yet to adopt a secure development process and often leave dangerous vulnerabilities unaddressed. Additionally, the study found that nearly all OSS communities fail to provide users access to security expertise to help fix these vulnerabilities and security risks.

The survey, sponsored by Fortify and completed by application security consultant Larry Suto, examined 11 of the most common Java open source packages.

Read the full article

Let's do Biz