NSS Labs vs. "some security vendors" and the Anti-Malware Testing Standards Organization

Going through some of the social media streams I'm following, my interest was drawn to an announcement made by NSS Labs (https://shar.es/a1GPSr) - as I was reading through the article, statements like "transparency and accountability in the cybersecurity industry", "flawed security product", vendor responsibility etc caught my eye. To my understanding the core of the article is about wether an organisation such as the Anti-Malware Testing Standards Organization can guarantee independent testing results if the majority of the members are security vendors ?

My intent is not to focus on who's wrong or right, nor to put any vendor mentioned in the article in the spotlight. Working for a security vendor, I'm often challenged by customers on the outcome of NSS Lab reports (and the likes) - mostly #Cisco security products fair well in these tests but we also have the occasional "bad outcome".

But what I would like to understand from you in customer land is how transparent are these reports (NSS Labs and the likes) for you? Does your organisation have a budget for these ?

Maybe its time for a independent standards organisation (and I don't know if they are already out there) that offers full transparency - these are the tests that we used, these were the outcomes, .... - lead by vendors and non-vendors, providing reports to the wider public free of charge - the Open Source malware and security validation lab.

It's early morning, the above is a braindump but I'm really interested in your feedback, ideas,...

PS: Please don't tell me that the testing methodology, the samples used, etc. need to be kept secret because we don't want the "bad actors" to get hold of them...I dont believe in security by obscurity


要查看或添加评论,请登录

?? Stefan Avgoustakis的更多文章

社区洞察

其他会员也浏览了