Both Independent Software Vendors (ISVs) and retailers with an Internet presence have struggled over how and when to release information to the public regarding security vulnerabilities and/or security breaches. This paper examines this debate and provides a potential conclusion.
From the Paper:
"In the modern age of information technology, security services and solutions are at the core of any organization's or Independent Software Vendor's (ISV) information technology strategy. Security is a baseline and absolute requirement for maintenance of an IT solution, yet it is often also one of the most difficult and dynamic components that IT managers have to contend with. In the past several years, reports of security vulnerabilities and associated attacks have reached ever increasing levels. Interestingly, most attacks occur after security vulnerability has been reported and a patch made available by an ISV."
More papers on Security Vulnerability and Incident Reporting:
Security Vulnerability and Incident Reporting (2012, January 15). Retrieved February 14, 2012, from http://www.academon.com/Analytical-Essay-Security-Vulnerability-and-Incident-Reporting/9514