A vulnerability is made public ... time passes ... a vendor issues a fix. Who did that the fastest in 2006? Are vendors getting better? Do the vendors fix High severity issues faster? Read on to find out ...
Data Center Directions Virtual Conference
Attend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.
Safeguarding the New Currency of Business
Watch this webcast to learn how your organization can leverage PricewaterhouseCoopers' Global Information Security Survey 2008, the world's largest survey on privacy and infosec practices.




.... jolly interesting and a nice argument. two points:
1. Unless I missed the point, it doesn't take into account type or severity of vulnerability. It is obviously debatable whether a DoS vulnerability should be treated the same as a remote execution vulnerability but I think may make a difference to the figures.
2. As we all know, an operating system is a bit like a chocolate teapot on its own. The comparison that would be REALLY interesting is Windows/IIS/SQL-S/.Net vs. LAMP.