Thursday | 20 November, 2008
IBM digs into security management
Big Blue claims it is on track to becoming a top provider of security operations
Matt Hines (InfoWorld) 08/01/2008 10:04:54

IBM is aggressively expanding its security portfolio in hopes of becoming the de facto source of advice and technology for businesses looking to adopt high-level IT governance and risk management strategies -- a transformation among customers that officials at Big Blue cite as both ongoing and inevitable.

As the waves of security threats and data management regulations have washed ashore and left organizations struggling to balance perimeter and internal security concerns with mounting obligations to protect highly-valuable data, companies are being forced to take more of a top-down approach that addresses broad sets of IT-oriented risks, versus individual problems, IBM officials maintain.

And while a host of players ranging from security software makers to massive IT consultants have begun marketing themselves as those best suited to help customers embrace a governance and risk management approach, IBM executives claim that their firm's mix of technology, services and partnerships place it at the top of any list of providers capable of helping organizations prepare their security operations for the future.

"We feel that we're ahead of the curve and driving forward our ability to meet these needs, some of which that might not yet have emerged from a broad perspective," said Kris Lovejoy, IBM's director of corporate security strategy.

"We feel that we are creating security risk management capabilities and have an opportunity to commoditize them in a way that can be leveraged at large," she said. "From an overall strategic perspective, that doesn't mean that customers are ready to stand up en masse right now and require everything we've built, but we're actively trying to extend the portfolio in advance of that trend."

Industry specialists, including Symantec and McAfee, the world's two largest security software makers, have also adopted high-level product and marketing efforts meant to help customers move away from battling individual threats and compliance regulations in favor of a more generic risk management strategy, but IBM claims that it is better positioned to help customers move in that direction today.

While the traditional security vendors have long been focused on shipping products that address various elements of end-to-end security and have only moved into risk management in the last two years, Big Blue has its own products and services as well as partnerships with those very vendors and many others that give it an upper hand, IBM executives said.

"In a sense, today, security is like a car without a steering wheel, and we think we're the only vendor who has the right abilities across all the involved domains that can drive change across business processes," said Eric McNeil, manager of corporate security strategy at IBM. "These other companies touch on a lot of domains, but we're the only ones who have all the pieces that span identity, applications security, physical security, and asset lifecycle management."

With its broad array of product and services skills, the executives said that IBM is best qualified to pull together key components that will allow more organizations to manage security using analytical reporting, policy creation and enforcement, and through the use of risk analysis dashboards.

The executives cite two areas, IT service management and master data management, as tremendously important to its ability to aid customers in addressing risk. To be able to build controls to oversee change and configuration issues on the services side and help companies get their heads around the intricacies of master data management, customers will need more than the traditional security vendors can offer, said Lovejoy.

"The security companies of the future are not the companies that offer capabilities for the newest bells and whistles, it's about those things and more, including all the plumbing needed to make these strategies work," said Lovejoy. "While traditional security players that off threat management have great benefits in securing a perimeter, they're not adept at installation of basic plumbing, which actually helps in managing the majority of the risk."

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Process Trip 04/02/2008 13:07:03

    Why Maritz Travel revamped key business processes — and how business and IT came together to make it work
    When Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    How to Get Real About Strategic Planning 04/02/2008 12:50:59

    Everyone agrees that having a strategic plan for IT is a good thing but most CIOs approach the process with fear and loathing. In fact, the majority of CIOs (and the enterprises they work for) are faking it when it comes to strategic planning. Isn't it time we all got real?
    Oh, it must be nice to be the CIO of a FedEx or a GE or a Credit Suisse. Places where IT and the business are so tightly aligned you can barely tell the two apart. Where corporate leaders understand that IT is a strategic asset and support it as such
  • +

    Toxic Mix or Bit of a Mixed Blessing? 31/12/2007 10:36:30

    “Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . ” The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare’s Macbeth, but even so it makes “for a charm of powerful trouble”
    "Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . " The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare's Macbeth, but even so it makes "for a charm of powerful trouble"
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101

Email archiving is emerging as a critical new application for managing email. Learn how to reduce and manage online and offline email storage, add powerful tools for legal discovery and compliance and extend native exchange recovery capability by reading on.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links