Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Getting the most out of open source without sacrificing security

Open source has seen a great deal of momentum among mainframers, making collaboration easier and providing greater transparency. But for all of its benefits, open source is not without risks. By its very nature, open-source code is accessible to whoever wants to see it—including potential attackers. That means an attacker looking to crack into an organization’s systems could simply examine the readily available open-source code and pick out vulnerabilities to exploit.

Overall, open source has incredible potential to help transform the way mainframe applications are managed, but it comes with risks that need to be properly addressed. So, where do businesses and IT leaders stand on the use of open source in the context of mainframe security? What are their concerns? And what’s being done to secure the mainframe as open source becomes an increasingly common tool for developers?

Rocket Software recently conducted a survey of 250 global IT directors and vice presidents in companies with more than 1,000 employees to find out. Let’s take a closer look at how these respondents view open source and mainframe security.

Open-source security on the mainframe

Open-source software has moved far beyond being a buzzword. Today, it’s a critical tool for organizations as they push to modernize in place with the mainframe. The collaborative element of open-source development means that the broader community is typically able to respond quickly to any issues, applying patches and fixes to critical vulnerabilities and exposures (CVE). But in a mainframe setting where IT leaders often deal with ported instances of open-source tools and languages—like a ported instance of Git operating on z/OS—those fixes and updates may not always make their way into the mainframe.

That means the open-source components embedded within mainframe applications, if not managed properly, could hold serious gaps in security and integrity. Among other mainframe security challenges with open source, there can also be compliance concerns that arise if an organization were to incorporate unsupported open-source software into its mainframe applications.

Keeping open source secure on the mainframe

So, we know the concerns that come along with the use of open-source software. But are the businesses and IT teams that lean on these tools prepared to handle those risks and respond accordingly? The good news is, based on the findings of Rocket Software’s survey, The State of Mainframe Security, it’s clear that the security of open source used on the mainframe is something organizations are taking very seriously.

Organizations understand just how important proactivity is to ensuring security, as 62% of survey respondents reported that their organizations routinely conduct vulnerability assessments and security audits. And another 58% of respondents said they engage in continuous monitoring and updating of open source to address security patches promptly. IT leadership in these businesses also understand the importance of preparing staff, too. Among respondents, 54% said they were training developers on best practices for secure coding and popper usage of open-source components. But respondents aren’t just relying on proactive measures; many reported having strong processes in place for managing the risks associated with open-source software on the mainframe. Eighty percent said they have a well-defined process for managing and monitoring the usage of open-source software in mainframe environments.

The state of open source on the mainframe

At a time when cyber threats are rapidly evolving, the ability of the open-source community to address vulnerabilities and put out updates and fixes has become critical. Fortunately, among survey respondents, 78% of organizations reported being highly confident in the open-source community’s ability to do just that and act quickly. Even as organizations get a handle on the way open-source software impacts their mainframe applications and security, it’s crucial that they work with a trusted source that can ensure critical updates and patches are ported to z/OS systems.

Learn more about how organizations are balancing the growing use of open-source software with mainframe security.

Security
Read More from This Article: Getting the most out of open source without sacrificing security
Source: News

Category: NewsNovember 13, 2023
Tags: art

Post navigation

PreviousPrevious post:4 steps to connect change management and DevOpsNextNext post:Where do IT leaders stand on securing the mainframe?

Related posts

IA segura y nube híbrida, el binomio perfecto para acelerar la innovación empresarial 
May 23, 2025
How IT and OT are merging: Opportunities and tips
May 23, 2025
The implementation failure still flying under the radar
May 23, 2025
보안 자랑, 잘못하면 소송감?···법률 전문가가 전하는 CISO 커뮤니케이션 원칙 4가지
May 23, 2025
“모델 연결부터 에이전트 관리까지” 확장 가능한 AI 표준을 위한 공개 프로토콜에 기대
May 23, 2025
AWS, 클라우드 리소스 재판매 제동···기업 고객에 미칠 영향은?
May 23, 2025
Recent Posts
  • IA segura y nube híbrida, el binomio perfecto para acelerar la innovación empresarial 
  • How IT and OT are merging: Opportunities and tips
  • The implementation failure still flying under the radar
  • 보안 자랑, 잘못하면 소송감?···법률 전문가가 전하는 CISO 커뮤니케이션 원칙 4가지
  • “모델 연결부터 에이전트 관리까지” 확장 가능한 AI 표준을 위한 공개 프로토콜에 기대
Recent Comments
    Archives
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.