Security demystified: Essential UTM tips
- 13 October, 2009 15:06
- Comments
In an effort to help IT managers better secure their organisations, Computerworld brings you answers - provided by AusCERT's experts - on a few of the more common questions around key security technologies. Here we look at United Threat Management (UTM).
What do you really need when it comes to UTM?
This is another question that each business will need to answer individually based on what they want to protect, and the anticipated level of exposure to threats.
Most firewalls these days are not classical firewall devices, they typically include some features that used to apply to the term “UTM”. With this in mind organisations considering a “UTM solution” should look at the following features:
- Simplicity – how easy is the device to configure and manage?
- What do I want the device to do? Antispam? Firewall? Content filter? Antivirus?
- Vendor responsiveness to support and device replacement. Remember you may be replacing a large chunk of our security infrastructure with this device.
- Does the product integrate well with my existing infrastructure?
- How easy is it to keep the device up to date?
- Does the vendor have a strong history in this area?
As with all technology, it must first meet the needs of the business, if you first establish these requirements, a matrix can be designed with which to compare products. What are the prime considerations for UTM?
- Selective SSL decryption capabilities (e.g. webmail but not internet banking)
- Active Directory or other directory integration functionality
- Support for multiple authentication mechanisms (RSA, Kerberos etc)
- Does the device work well in a failover configuration?
- Does the device work well in a failover configuration?
- Does the device support High Availability (HA) configurations?
- Is the device capable of using redundant ISP settings?
- Granular configurable reporting and blocking is usually desirable.
- Simple updating with data from multiple sources, including up to date vendor “known bad” lists, and bulk rule updating.
- Deep packet inspection capabilities may be highly desirable.
- VPN capabilities may be desirable.
- Remote encrypted logging capabilities.
- Multi user with configurable access levels.
- Do fit a solution to the problem you’re trying to solve, rather than simply purchasing a product because of all its bells and whistles.
- Do thoroughly assess the protections offered and how they map to your business requirements.
- Ensure the system matches the risk profile of the business.
- Avoid including features you don’t need, and can’t turn off.
Remember that when you consolidate security infrastructure in this way, a remotely exploitable vulnerability in any component of the UTM system can disable a significant portion of your security infrastructure. Make sure you have a plan for such a contingency.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
-
CeBIT 2012: Will NBN speed up freight delivery times?
-
NBN build gaining momentum daily: Quigley
-
Coalition NBN better or worse?
-
TPG faces customer backlash over slowed net speeds
-
CSIRO claims world's fastest wireless link
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
MYOB Software for Dummies 6E Australian Edition
-
Teach Yourself Visually Windows 7
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Windows 7 for Dummies®









Comments
Post new comment