The Philadelphia Stock Exchange flows 300 million stock quotes per day over an electronic trading system at rates that climb as high as 20,000 quotes per second during peak periods. The systems also churns out extremely sensitive trading reports packed with proprietary customer information that must be stringently guarded from outside attacks and unauthorized internal access.
And beefing up security isn't the only challenge facing IT executives at the PHLX. Stock-trading information must be accessible to customers at all times. Therefore, the PHLX streams stock quotes, a practice that requires technology officials to comb the system constantly for attacks. Security measures include alarms and triggers so sensitive that even benign cases of runaway streaming will mimic denial-of-service attacks and kick off a series of safeguards.
Like most other large organizations, the PHLX is armed with firewalls, intrusion-prevention systems (IPS) and elaborate audit trails. The goal is air-tight security -- and reaching that goal is a daunting challenge, considering the complex infrastructures that exist in most big organizations.
"We have placed layers and layers of multiple vendor products to surround our networks with so much protection that we have created a defence akin to the Castle Keep," says Bernard Donnelly, vice president of the PHLX's quality assurance group.
But those safeguards deal with only part of the threat. "Don't become so overly focused on keeping intruders out that you leave yourself vulnerable to internal threats," says Donnelly.
Employees can walk out the door with gigabytes of sensitive data on tiny removable storage devices. Often overlooked are everyday occurrences, such as loud mobile-phone conversations that reveal too much in public places like airports, says Eileen Hasson, president of IT services firm The Computer Company Inc.
Sadly, there's no one-size-fits-all model for protecting private information. The good news is that IT officials can learn from people in industries on the front lines of guarding precious customer information. "There are no guidelines for enterprises, except perhaps those being adopted by financial services and health care industries," says Hasson. Those industries are leading the way on privacy protection because the stakes are so high for them.
"Failing to comply with HIPAA mandates regarding protected health information has severe penalties and would not only compromise but cripple our business," says Gary D'Amato, systems manager at Health Access Solutions, a provider of IT services to the health care industry.
At Care New England Health System, compliance with the Health Insurance Portability and Accountability Act centred on an exhaustive gap analysis of the organization's computer network and major penetration testing -- an elaborate exercise that often frames corporate security plans, says IT security manager Larry Pesce.
Gap analyses entail top-to-bottom reviews of security policies and often wrap in all rules and regulations imposed on a particular organization. In Care New England's case, the analysis started with mapping HIPAA mandates to internal security policies and procedures. It soon became evident that the organization's security mechanisms fell short of HIPAA requirements. Security audits were in order, says Pesce.
"I knew the only way to get the audit results I needed would be to start performing regular penetration testing," says Pesce. "From my experience, I knew that would give me the most accurate view of the network and provide me with the precise audit information I would need."
However, Care New England's gap-analysis efforts proved onerous. "Manual testing placed a tremendous strain on my limited budget and resources," Pesce says. "It was time-consuming to write exploits, ensure they were safe to run, perform the attack, and update and manage the process." Finally, he eased these burdens by adopting Core Impact, an automated testing framework from Core Security Technologies in Boston.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
Making the Business Case for IT Consolidation
Discover the advantages of an open architecture multi-vendor network solution
The state of Middleware
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
Best Practice in Building an Integrated Information Management Strategy
Email Archiving 101—Customer Case Study
Solve Exchange Mailbox Storage Issues Once and for All
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Sterling Commerce Speeds Long-Distance Delivery of Large Files 2008-12-03 09:28:00+11
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Everything you need to know about email and web security (but were afraid to ask)
What you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.












