Computerworld
Sun exec: IT security should follow business needs
Proscriptive adoption of information security standards like ISO27001 is bound to fail, Sun's chief technologist says.
Jared Heng (IDG News Service)  30 October, 2008 09:04

Proscriptive adoption of information security standards like ISO27001 is bound to fail, according to Joel Weise, principal engineer and chief technologist, Sun client services security program office, Sun Microsystems.

"Organizations that take the proscriptive approach see security standards as 'to do' lists, when in fact they are only suggested frameworks," Weise said. "This approach will never work as it simply does not consider the organization's particular needs."

Weise said that organizations should build specific security architecture for their particular IT infrastructure that is applicable to business and technical needs.

To build security architecture, the organization should consider an 'adaptive security' approach, Weise said. "Adaptive security is a framework for elaborating a comprehensive architecture that enables cost effective risk management for threat containment," he said. "It also seeks to improve operational efficiency and system survivability."

Business complexity

According to Weise, Sun's chief technologist office team came up with the concept of adaptive security, based on works by others.

"Our observation that biological and ecological systems appear to have very reasonable survival capabilities drove the emergence of this concept," Weise said. "So we looked to nature for an appropriate security metaphor."

Feedback from Sun's customers that the business environment has become too complex for the IT department to deal with is another driving factor, Weise said. "For example, the rise of the internet and managed services has added to complexity."

Weise noted that as environmental complexity increases, system security decreases. "Threats are developing faster than counter-measures, while a homogenous IT environment allows a 'pandemic' to spread quickly."

The chief technologist pointed to the parallel situation in nature where H5N1 bird flu has caused high mortality rates among infected people. "In the same way, if a cyber attack brings down one server in a data center, all other servers may follow," he said.

"Adaptive security seeks to mimic biological auto immune systems at the microscopic level and ecological systems of disparate entities at the macroscopic level," Weise said. "It is not defined by a single system or process."

Adaptive security

Biological systems use immune systems to dynamically respond to threats, while stem cells can be used as a foundation to 'repair' other body elements, Weise noted. Additionally, the human body can discriminate between 'self' features and foreign bodies like liver transplants, which may be rejected.

From a macro perspective, survival of the ecological system does not depend upon the survival of any individual entity. "Ecosystems are by definition diverse and this contributes to their resilience," Weise said.

Weise said that in the same way, IT systems may be designed to adaptively respond to different threats, with self-regulating, self-healing and self-protecting abilities. "This includes the ability to 'know' normal conditions and detect abnormal system behaviors."

Specifically, adaptive security seeks to reduce threat amplification, area vulnerable to attack and system recovery time in the event of an attack, Weise said. Other objectives include ensuring availability and reliability of data and processing resources, as well as reducing attack speed.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Understanding Email Marketing: A Guide for SMBs

Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.