Security Assurance for Commercial Off-the-Shelf Systems
When managing security risks, in an organization's technology environment, it is essential to understand the nature and limitations of commercially acquired software products.
2 slides · 1 min read · Domain 8
In most cases, the majority of software systems and elements in use by an organization are acquired as commercial products sold or licensed as commodities. These are commonly known as commercial off-the-shelf (COTS) software, firmware, or embedded products. Copies of firmware loaded into processor motherboards or device controllers, operating systems, standalone applications or productivity suites, and application platforms are typically acquired off the shelf and integrated into the organization's overall IT infrastructure. In almost all cases, the organization does not have the capital or other resources to exert significant influence on the developers of these commodities to ensure that specific security or other software assurance needs are met.
However, the security professional is not without options when advising their organization on achieving some degree of software assurance in these cases.
Systems, products, and even retailer or wholesaler selection are decisions that can and should be influenced by security considerations.
Leverage the Common Vulnerabilities and Exposures (CVE) database to review known vulnerabilities for products under consideration, as well as for other products made by the same vendor. Research each vendor's track record in addressing reported vulnerabilities, issuing timely security updates, and distributing those updates through securely signed packages. The same due diligence you would use to keep such a system operating securely after installation should be applied before endorsing the decision to buy, lease, or license it for use.
