Who Is Liable for Insecure Systems?

  • Authors:
  • Nancy R. Mead

  • Affiliations:
  • Software Engineering Institute

  • Venue:
  • Computer
  • Year:
  • 2004

Quantified Score

Hi-index 4.10

Visualization

Abstract

Over the past several years, we have seen both the enactment of legislationaffecting liability and the appearance of actual liability cases in the courts.Although several software flaws can make systems insecure, an entire industry including software vendors, systems administrators, consultants, network technicians, and clearing houses has developed to try to mitigate security holes after the fact.Nevertheless, the issue of liability lurks just beneath the surface of all their activities. Although the courts may not be the best venue for resolving this, liability cases will take place and an evolution of best practices will occur as well.