SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Leadership >> Issues for CIOs

Change security tactics: experts

Change security tactics: experts

By:  Chris Conrath  On: 02 Sep 2004 For: ComputerWorld Canada Creator

Today’s increasingly hostile IT environment is forcing companies to come up with new strategies to defend their data, according to participants at a security roundtable held in Toronto last month.

Today’s increasingly hostile IT environment is forcing companies to come up with new strategies to defend their data, according to participants at a security roundtable held in Toronto last month.

The statistics back up this apparent increase in malicious code. There have been more level three and level four (out of five) worms, Trojans and viruses in the first six months of 2004 than all of 2003, according to both Symantec Corp. and McAfee Inc.

As Canadian companies acquire more and more technology, they will have to learn of ways to “devolve” security from an entity traditionally owned by corporate security to one where it is controlled by individual job roles, said Robert Garigue, chief information security officer with BMO Financial Group.

Garigue said firewalls, for example, have “devolved” from a security appliance to a network appliance issue, one no longer controlled by the security arm of a company. Acceptable firewall parameters are still dictated by security, but network administrators control the day-to-day operations. It is important for security best practices to become an operational issue and “part of the textures of the (job) routines,” he said. In order to do this, Canadian banks are creating a foundation for knowledge transfer, so best practices become routine, he said. Garigue is the chairman of a group of financial institution vice-presidents who work together to achieve this goal.

Another security strategy increasingly used by corporations, according to both John Weigelt and Jack Sebbag, is the notion of defence in depth. This strategy involves both an increased relationship between policies, procedures and products in the corporation as well as a noted consolidation of vendor technology in the market, where one vendor offers many layers of defence.

“We are seeing [companies] focus on the complete picture,” said John Weigelt, chief security advisor with Microsoft Canada Co. Customers are taking an indepth look at that happens when one component fails within a system and how other technologies and procedures seamlessly take up the work load when a system fails, he said.

This is a good strategy since “there is no 100 per cent security,” agreed Sebbag, the Canadian general manager of McAfee Inc. Sebbag also pointed to a confluence within the security vendor market, as a bit of buying spree is going on. Larger players are buying smaller, niche, security companies to round out their offerings. McAfee recently bought Foundstone, a vulnerability management company.

Garigue also said technology “vendors recognize that they have to share a lot more information” with their clients about their technologies so that companies can get “policies at all levels to talk to each other.” For security to work, “that whole stack...from mainframe to consumer...has to be aligned,” he said. Both Sebbag and Weigelt agreed that improved communication between vendor and client is needed. Microsoft often points to the fact that last year’s Blaster worm was successful because systems were not patched, though a patch was available. To streamline the communication between vendors and clients, and to simplify the process, Microsoft has limited patch releases to the first Tuesday of each month.


Sign up for our Newsletters












Print |  Views: 504   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Chris Conrath Chris Conrath is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Feeling insecure about Vista
Feeling insecure about VistaDespite assurances from Microsoft, security vendors are wary that the software giant has not given a definite timeline for releasing code to allow third-party security software to work around the Windows Vista operating system kernel protection for 64-bit systems.
VoIP security relies on interoperability
VoIP security relies on interoperabilityLack of equipment interoperability and confusion over security responsibility are to blame for the lack of security in voice over IP (VoIP), an issue that IT administrators say is a major concern for them, experts speaking at last month’s VON Europe conference said.
Senior security product manager at Microsoft Canada
Senior security product manager at Microsoft CanadaCiting customer demand and massive testing efforts, Microsoft Corp. released a patch last Thursday, several days ahead of schedule, for a vulnerability in some Windows graphics files.
Does Virtualization Equal ‘Bullet Proof’?
virtualization has been available to the it world for more than four decades, yet it has still not really taken off in the multi system environment.  many vendors are pushing this approach to deploying ‘flexible technology’, yet it still has not emerged beyond the ‘glass house’ of the data centers or server closets.  ibm i
Advertising has a new angle: the economy
i heard an advertisement on the radio a few weeks ago from a vendor of home appliances that read: “quality appliances hold their value in any economic climate.” and, a few days ago, i saw a tv commercial for an automobile manufacturer that had a similar ring: “finance or lea
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof
blog comments powered by Disqus