CLICK for Home Page and HR Administration Overview
Website Launched:  12/26/1994
Last Update:  2/14/2013
The Integrity Center, Inc.

(972) 484-6140
[ Since 1984 ]
HOME Reference Articles
 
SCREENING
Check List
Backgrounds
TUTORIALS
SERVICE MENU
FCRA
THIS COMPANY
Our Methods
Why Use Us
Myths
Pitfalls
CHECK MYSELF
CHECK NANNY
USEFUL LINKS
Library
Statistics
PRESS RELEASE
The Integrity News
Vol. XIII No. 14
ISSN 1081-2717

July 23, 2004 


Federal Computer Week
July 19, 2004     (pgs. 60-62 )


 
The Outsourcing Hole
( That hole in our national security from
outsourcing software writing overseas. )



The U.S. Military is tending to buy much of the same software that we use commercially.   The problem is "that the vendors are sending much of their software development work overseas to cut costs.   But, the security ramifications are starting to raise red flags for Congress, the Pentagon, and the vendors."   We warned of this problem in an issue of The Integrity News, in November, 2003.

Commercial software was never intended to be subjected to the significant threat level that important companies and the DOD face today.    For much of today's existing code, it is impossible to "determine the code's authors, their intentions, or their politics."    "Using foreign labor has been wonderful for the economy, but it has introduced tremendous vulnerability to our software."   It is expected that spending for offshore information technology services will increase from a few billion dollars in 2004, to $26 billion in 2007.

Aside from the national security risks, "companies that ignore outsourcing trends do so at the peril of their own long-term competitiveness."   "Someone with a malicious  intent could easily develop a Trojan Horse, a Back Door  into the application, or a Time Bomb."

"Our current national policies that are intended to mitigate information system vulnerabilities, focus mostly on operational software security threats such as external hacking and unauthorized access.    These policies do not address insider threats such as the insertion of malicious code by software developers."    ( We explained this in detail in a November, 2003 issue.)

Imagine "a terrorist cell that trains a group to be software programmers, then infiltrates companies that have sent their software development work overseas.   Working for those companies, the programmers could surreptitiously  put vulnerabilities in the software."   This potential puts a whole new meaning on Personnel Security.

All programmers at The Integrity Center, Inc., like all employees here, are each licensed Private Investigators  who have had a background check by the FBI.

"There is a growing demand
for software accountability."

    "Due diligence in providing assurances that software
applications are trustworthy and secure.

    More care in developing requirements for software
coding jobs that are sent overseas.

    Removal of sensitive portions of software coding such as
business logic or security, from jobs sent overseas.

    Testing of software much earlier in the development
process.

    Software warranties or service-level agreements
that hold vendors responsible."

"Private sector companies share the worries of their government counterparts.   But, outsourcing software isn't going to stop now."    "Economics are dictating software development, and as much as vendors aren't really comfortable with it, the financials of outsourcing will continue to drive it."

"We have to recognize who we have been up against so far.   Its been script kiddies in schools, and pranksters.   The people we need to worry about, and haven't been, are the professionals."

For more information about background checking, visit our website, or feel free to call The Integrity Center, Inc.   at   (972) 484-6140.   Helping you with your Risk Management and HR Automation is what we do.


EARLIER
NEWS ITEMS
The Resume
   Problem
Immigration Reform
   Will Mean:
   Employers MUST
   Enforce
   Employment
   Eligibility
   Verification
Economic
   Espionage
Guerrilla
   Reference
   Checks
The Mobile
   Integrity
   Connection (tm)
NEW U.S.
   Law Increases
   Employer Risk
Time
   To
   Shred
Three New
   H.R. Videos
"7 Ways
   To Avoid
   Employees From
   Hell"
Form I-9 Update
   and NEW
   Form I-9 Tools
New Federal Laws
   To Consider
Access To News
   Items For HR
   And Security
   Professionals
Sarbanes-Oxley
   and
   Background
   Checking
Using
   Credit Bureau
   Reports In The
   Hiring Process
Talent Assessments
   Before Mergers
   Acquisitions
   or Investments
Vicarious
   Liability
Medical
   Identity Theft
Federal
   Civil
   Litigation
   Histories
New Items
   for HR and
   Security
   Professionals
Employers
   Offer Help
   Fighting
   I.D. Theft
Avian Flu:
   Business Thinks
   The Unthinkable
New Federal
   Rules That
   Govern Online
   Recruiting
Gaffe Shows Need
   To Screen Current
   Employees At
   Promotion Time
The
   Baby Boomer
   Exodus
Document
   Disposal Law
   Kicked In
   June 1, 2005
A New Wrinkle
   On Age Bias
Don't Let Your
   Vendors
   Compromise
   Employee
   Identity Data
Annoying Hacking
   Has Now Become
   Organized Crime
Persuading
   Your Company
   Management To
   Encourage
   Training
Mainstream Media
   FINALLY Address
   Risks Of Using
   Databases For
   Employment
   Screening
HR Automation
   Can Improve
   Company Finances
   And Innovation
Employers Beware
   The
   "Seal of Approval"
Identity
   Verification
The
   Outsourcing
   Hole
Cyber Age
   Employee Crimes
Security Risk
   From Mobile
   Media Devices
More FCRA
   Amendments
   Could Be Coming
   By Year's End
The FCRA
   Was Amended
   On 12/4/03
Physical Security
   and Information
   Security are
   Merging
Increase
   HR Productivity
Homeland
   Security
   Guidelines
Sarbanes-Oxley:
   Road To
   Compliance
WARNING
Stored Data
   Warning Signs
How to FIND,
   FIX or FIRE,
   Your POOR
   PERFORMERS
ID Verification --
   Inexpensive and
   VERY Effective
The Darkest Side
   Of Identity Theft
Companies Dig
   Deeper Into
   Executive's Pasts
Fraud And New
   Scrutiny Of
   Executives
Be Careful With
   Instant Messaging
   and Wi-Fi
STRESS
Identity
   Management
California
   Data Privacy Rule
Obtaining
   Criminal Histories
   In New York State
"The Privacy Rule"
   in HIPAA
Putting A Crimp In
   The Management
   Of Spam
New Technology
   Facilitates
   Corporate
   Espionage
Identity Theft
   Checklist
Monitoring
   Employees
The Domestic
   Security
   Enhancement Act
NEW
   Overtime
   Pay Rules
The High Cost
   Of Penny-Ante
   Scams
"Signs" That
   You Need To Do A
   Periodic Check
FTC Charges A
   Company With
   FCRA Violations
The NEW
   Integrity
   Connection (tm)
Workplace
   Safety
   Checklist
HR is Splitting
   Into Two
   Separate Parts
Keep Your Eye On
   RFID Technology
Improv At
   The Interview
Real Security
   Won't Come Easy
   Or Cheap
DOs & DON'Ts
   To Minimize
   Violence
Identity
   Theft
Snapshots of
   Federal Laws
TIPS for
   Gramm-Leach-Bliley
   Compliance
The Sarbanes -
   Oxley Act
NEW Calif.
   Background
   Checking Laws
The Benefits
   Of Online
   Job Applications
Compensation
   --- Now It's
   Getting Personal
The United States
   Security Network
Supreme Court
Limits ADA
Supreme Court Will
   Review Law On
   Age Discrimination
Management Sleaze
The Examiner (tm)
Helps You Uncover
The New Face
Of Corporate
Responsibility
The Sarbanes-Oxley
   Corporate
   Reform Law
The Corporate Spy
National Wants and
   Warrants Illegal
No Dangerous
   Jobs For Disabled
Security
   Precautions
   for Businesses
Terminating
   An Employee
Listening in an
   Interview
Arbitration
   vs.
   Litigation
Supreme Court
   Eases Rules for
   Workers Who Sue
Drug Abuse
   Statistics
The Enemy
   Within
Priority:
   Integrity
Funding Terrorism
   With
   Information Theft
Corporate America
vs.
Copyright Theft
Mental Illness
   Workplace Costs
How to
   Fire Properly
Lying
   On Resumes
Workplace
   Guidelines
   To Be Voluntary