Read up on the latest ideas and technologies from companies that sell hardware, software and services. Taking On Demand CRM Integration to the Next Level
Revolutionising Back-up and Recovery
Wireless LANs: Is my enterprise at risk?
Cutting printer costs
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Delivering the Power of Choice with Microsoft Dynamics CRM
Improving Sales Productivity: An Opportunity for Sales and IT Leadership
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Remember the old M&M analogy - security is like an M&M candy, hard shell on the outside, soft on the inside. In other words, put up firewalls, built a strong perimeter and you're good to go. Of course, nobody believes that M&M-type security is sufficient in today's world of insider threats, data leakage, mobile workers, thumb drives and sophisticated malware. So, what's the new metaphor? We asked around and came up with a number of interesting and useful ways to think about enterprise security.
Security is like a stack of Swiss cheese
Each slice covers up holes in the slices below it. By Jeremiah Grossman, CTO, Whitehat Security.
Traditional enterprise security is viewed as a hard outer shell protecting a soft interior, but today's Web 2.0 era has changed all that. The perimeter has become porous with applications and access control shared deep between enterprises and consumers. In this way enterprise security can be best viewed like a stack of Swiss cheese. No single layer of security is impenetrable; each protects certain areas and misses others. In a layered approach each slice (defense-in-depth) attempts to cover up the holes in the one below it.
Security is a fortified castle
Defenses are needed on the perimeter and inside. By Ryan Sherstobitoff, Panda Security.
Today's threats are designed to evade multiple layers of defense and the M&M metaphor no longer applies. Emerging threats are able to bypass current perimeter defenses (the shell) and invade end-points because the vector has changed. This perimeter-based model worked years ago during the days of network worms, network based attacks, when they were easily stopped by blocking ports. When talking about network security today, both a perimeter and a converged end-point approach, including many different technologies (antivirus, data leak prevention, system hardening, disk encryption, behavioral blocking, behavioral analysis, firewall and NAC) that inspect and prevent at multiple layers is key.
Security is like a primary care physician
Coverage needs to extend from cradle to grave. By Becky Bace, Trident Capital.
The body of knowledge associated with system security/risk management has grown explosively over the past couple of decades and we're at a generational juncture. It's time for us as a profession to acknowledge this and to adjust our definition of roles and requisite expertise accordingly. I use the analogy of healthcare to describe where we are and where we might want to go. The notion of primary care provider (i.e. family/personal physician) is core here, with qualifications determined by not only how well the person understands core concepts of security, but also how well the person understands the system (and associated business) to be protected. I also propose that we define and provide some way of rigorously assessing and certifying specialists who would be called in when an issue falling within their specialty arose. One of the points of this analogy that I like the most is the notion of specialty coverage from womb (obstetrics) to undertaker (forensic pathology), for good security has that level and range of involvement.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Did you GET the memo? Getting you from Web 1.0 to Web 2.0 Security
Enterprises have forged ahead with the rapid evolution from Web 1.0 to Web 2.0 without addressing the inherent security risks. It is imperative for organisations to continue to embrace new technologies to survive, but security must shift from being an after thought to a primary consideration. Read on to find out more.










