On CNET: Wi-Fi alarm clock with Internet radio
BNET Business Network:
BNET
TechRepublic
ZDNet

By Jon Oltsik, News.com
Posted on ZDNet News: Dec 10, 2004 1:11:00 PM

Commentary--If you want to see a good example of security, think of your local bank.

At many large branches, customers are greeted at the front door by an armed guard providing perimeter security. Inside, the bank is well-equipped with security cameras for surveillance and manual alarms that can be activated by threatened tellers.

The last line of defense of course is the bank vault itself. Securing the money in a safe means that bad guys have to go to extraordinary lengths (think dynamite or safecracking) to pull off a heist.

This classic "defense in depth" architecture protects every layer of the infrastructure and is the basis of all good security models. Take Visa's Cardholder Information Security Program, or CISP, for example. Mandated in 2001, the program defines 12 security standards for all Visa payment system constituents. The standards include perimeter security, ongoing surveillance and protecting critical data at rest and in flight.

Visa clearly understands the risks of weak information security on its business, which is why it demanded CISP compliance. Service

When it comes to protecting the crown jewels (aka corporate information) few companies do anything.
providers were told to submit compliance documents by September 2004, to conduct quarterly system perimeter scans and to update documentation on an annual basis.

Compared with systems at other enterprises, CISP is like Fort Knox. Most companies still dedicate most of their security budget to perimeter products such as firewalls and filtering gateways--and things go downhill from there. Businesses tend to pay marginal attention to surveillance by setting up chatty Intrusion Detection Systems, or IDSes, and occasional system audits.

When it comes to protecting the crown jewels--that is, corporate information--few companies do anything. Servers maintain default configurations, loads of system administrators have root access, databases are tuned for performance not security, and information is stored on open storage platforms in clear text.

Anyone else thinking "Swiss cheese" at this point?

Confronted with this situation, many companies freak out and rush to find an encryption tool to protect their intellectual property. I think this has something to do with the popularity of Dan Brown novels myself, because encryption is only part of the solution. If I can break into the server, or exploit database or system vulnerabilities, I can still get access to encrypted data--every time.

The first step here isn't nearly as sexy as encryption: It's boring, old audit. For example, remember Oracle's "unbreakable" campaign?

There are simply too many risks and vulnerabilities out there to continue this type of irresponsible behavior.
Well, Larry Ellison's software company has issued six major alerts for Oracle products in 2004 alone. Systems need to be audited for patches, stale accounts, default passwords and configuration problems.

Since many small businesses just don't consider security, database-penetration testing, vulnerability and (yes) encryption, tools from companies such as Application Security can help. The same is true of host vulnerability-scanning software from providers such as Foundstone (McAfee), Internet Security Systems and Symantec.

Moving down the proverbial technology stack, storage infrastructure seems to have a permanent spot at the back of the security line.

In a recent Enterprise Strategy Group survey of end users, 30 percent of respondents said their information security policies and procedures don't include data storage technologies such as storage arrays; Storage Area Networking, or SAN, switches; or storage management software. Eight percent of storage administrators and 16 percent of security administrators believed their storage infrastructure was insecure. Only 37 percent of the respondents claimed that their companies had undertaken a storage security audit. Does anyone else want to stuff their money into a mattress?

Again, this doesn't need to be the case. Service offerings from @Stake, Glasshouse and McData specialize in storage security audits and remediation. Storage security technologies from Decru, Kasten Chase, NeoScale Systems and Vormetric are slowly gaining visibility.

Even with some of these leading-edge technologies available, will anything change? You bet it will. Chief financial officers loathe spending money on insurance such as information security technology, but they hate having their intellectual property lifted a heck of a lot more. Marketing executives feel pretty foolish when national headlines describe how the company's customer database was cracked by some "Star Trek"-loving system administrator.

Finally, let's not forget those government wonks with the ever-growing list of regulations. These aren't isolated issues; they have an impact on companies every day. Something tells me there will be less rhetoric and more vaults, moving forward.

One additional security cliche warns against locking the doors but leaving the windows wide open. Leaving corporate data unprotected is clearly an example of this. Let's face it: There are simply too many risks and vulnerabilities out there to continue this type of irresponsible behavior. Heck, Visa certainly recognizes this and is mandating changes to its constituents. Smart companies will respond quickly to protect themselves and their customers, while fools will wait for further regulations or costly breaches before they learn.

biography
Jon Oltsik is a senior analyst at the Enterprise Strategy Group.

  • Talkback
  • Most Recent of 34 Talkback(s)
Very interesting
and a good article.

However, I would say that your bank example was not completely accurate.
If one is allowed through the bank's front door; behaves impeccably for the sake of the cameras;... (Read the rest)
Posted by: douglen@... Posted on: 12/24/04 You are currently: Logged In | Log out
Government and sensible "does not compute" alterego_z   | 12/10/04
Talk Back Is Useless nikoli   | 12/10/04
And at Zdnet, FilledOut   | 12/10/04
A "decent article" wouldn't "condemn" anybody. Judas I.   | 12/10/04
It looks like you have no idea ... Vily Clay   | 12/10/04
It looks like you have no idea ... htotten   | 12/10/04
htotten, you "love" US merchants as G.W. Bush ... Vily Clay   | 12/10/04
As I said before: htotten   | 12/12/04
A few banks? How about JP Morgan with satellite banks, Hobart, etc.? Vily Clay   | 12/12/04
You answered for me.... htotten   | 12/12/04
But you, htotten, understood nothing. No surprise. Vily Clay   | 12/12/04
It's visa and mastercard who are supposed to ensure traders are valid hipparchus2000   | 12/12/04
They do. htotten   | 12/12/04
only traders can take money from a persons card hipparchus2000   | 12/12/04
How? htotten   | 12/12/04
htotten, are you a member of the Bush administration? Vily Clay   | 12/12/04
Unfortunately Banks get robbed too !!! realitycheck101   | 12/10/04
But how do your really feel? No_Ax_to_Grind   | 12/10/04
Hehe NonZealot   | 12/10/04
Gee... htotten   | 12/10/04
was the sco website hacking ever proved? hipparchus2000   | 12/12/04
I have never said htotten   | 12/12/04
generally it is accepted that monopolies hold markets back hipparchus2000   | 12/12/04
So what you are saying is that htotten   | 12/12/04
Oh, and I forgot htotten   | 12/12/04
geez what a lot of technical errors hipparchus2000   | 12/14/04
The best protection you can have from the government ... Vily Clay   | 12/10/04
Nice article Jon Roger Ramjet   | 12/10/04
Finally, a sensible security scheme ... michael-t   | 12/10/04
You dont have to do Windows AdeOghert   | 12/10/04
arggh not this again hipparchus2000   | 12/12/04
No OS is infallible wresnick   | 12/14/04
Good article. htotten   | 12/10/04
Very interesting douglen@...   | 12/24/04

What do you think?

advertisement
advertisement

Whitepapers & Webcasts