[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Fwd: NDA & SOX?
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Fwd: NDA & SOX?
- From: Christoph Gruber <grisu@xxxxxxx>
- Date: Fri, 11 Mar 2005 10:35:59 +0100
Ahoi!
Listening to a presentation on Thursday I wondered about the follwing thing:
SOX (Sarbanes Oxley Act 2004) forces the disclosure of information which
could be relevant to investors (very short form).
For example: If a manufactorer of cars gets to knowledge of a certain
weakness in his cars, he has to call them back and inform the public
IMMEDIATLY about that thing.
If a manufactorer of software gets to knowledge of a certain weakness
(vulnerability), does he have to inform the public immediatly?
Is it even worse, if the manufactorer forces everyone, who has knowledge
about that thing, to sign NDAs?
What do you think about that?
Please excuse my bad english.
--
grisu
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://www.secunia.com/