Almost half of U.S. companies say that known operating-system flaws were a primary means used in the past year to attack their systems, according to InformationWeek Research's Global Information Security Survey. That's up sharply from a third in 2001. So it's no surprise that improving operating-system security, cited by 63% of North American companies, is the highest tactical priority for the coming 12 months. What's unsettling is that security managers won't find a great answer to their problems.
A final option hasn't caught on beyond industry-specific uses such as governments and financial institutions. It requires scrapping the more popular operating systems for what are known as trusted, or hardened, operating systems. The notion dates to the early 1980s, when the Defense Department and intelligence agencies developed a set of standards aimed at creating impenetrable computing systems. The Trusted Computer System Evaluation Criteria standards, commonly known as the Orange Book, were made publicly available but never took off.
A few companies sell hardened operating systems, such as Argus Systems Group's PitBull LX for systems based on Linux, Solaris, and AIX; Hewlett-Packard's Virtualvault, a trusted version of HP-UX 11.0; Sun's Trusted 8 Operating Environment; and SGI's Trusted Irix for Unix. These replace the operating-system kernel with one that restricts which operations a user with root access can perform, so an intruder can access only a small part of the system.
Super security used to sport a super-sized price tag, but these systems have become more reasonable. Argus' PitBull LX starts at $3,000.
But most managers still come out like Brian Amirian, the hosting director of a major entertainment company that considered, but rejected, a hardened operating system because of higher management costs and incompatibility with custom applications.

Boeing seeking Software Engineer 5 in Anaheim, CA
KForce seeking Inside Sales Associate in San Diego, CA
Amalgamated Bank seeking Chief Information Officer in New York, NY
Apollo College seeking Medical Billing and Coding Instructors in Albuquerque, NM
Allstate seeking Exlusive Agent in Las Vegas, NV
For more great jobs, career-related news, features and services, please visit our Career Center.
10 Steps For Stronger Application Performance
Subpar application performance has an impact-on employee productivity, perception of IT, and the expectations customers and partners have about your organization's overall ability to deliver. We can - and must - do better. Here's how.
read more 
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.