Don’t get me started about ISO. They can go fuck themselves.
But that particular standard doesn’t apply to software. It applies to a company. Its a best practices, audited authoritative report. None of that means the software doesnt have backdoors, flaws, issues, its how they handle them.
Microsoft is a known ISO cheater, and will pay off companies or at least influence them, so I wouldn’t trust ISO or the auditors.
So now, any company that is willing to take on the challenge of being certified can use open source software (which actually is audit-able as opposed to Microsoft’s).
Seems like there is a path forward. Yes they may have to fund a project that helps audit, develop, or maintain critical software. If its open source, you have an entire world could also participate in securely developing software, in the open.
Don’t get me started about ISO. They can go fuck themselves.
But that particular standard doesn’t apply to software. It applies to a company. Its a best practices, audited authoritative report. None of that means the software doesnt have backdoors, flaws, issues, its how they handle them.
Microsoft is a known ISO cheater, and will pay off companies or at least influence them, so I wouldn’t trust ISO or the auditors.
So now, any company that is willing to take on the challenge of being certified can use open source software (which actually is audit-able as opposed to Microsoft’s).
Seems like there is a path forward. Yes they may have to fund a project that helps audit, develop, or maintain critical software. If its open source, you have an entire world could also participate in securely developing software, in the open.