SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Security management, SaaS headline CAWorld

Security management, SaaS headline CAWorld

By:  Rafael Ruffolo  On: 17 Nov 2008 For: ComputerWorld Canada Creator

The global recession has made its presence felt at this week’s CAWorld 2008. Read about the company’s plans on security management for outgoing enterprise data in the face of more and more IT outsourcing

LAS VEGAS - With IT managers increasingly outsourcing their key infrastructure to third-party service providers, security and risk management is getting lost in the shuffle, according to CA Inc.

To address this, the company announced the release of two new CA Identity and Access Management (IAM) upgrades designed to strengthen security for external IT services.

During Monday’s sessions at CAWorld 2008 in Las Vegas, nearly every CA executive stressed the need for IT to adapt to the sputtering economy and reduce unnecessary spending wherever possible. With capital budgets for new IT projects at a complete standstill in many organizations, CA argued that companies have almost no choice but to move some IT services to a hosted, pay-as-you-go model.

Dave Hansen, corporate senior vice-president and GM of security management at CA, said that as individual business units such as marketing, HR and sales continue to go around IT and sign-up with their own Web-based consulting services, the need to secure and authenticate outgoing data is crucial.

“Salesforce.com is not a trivial thing to roll out,” he said. “Data is leaving your environment and you can’t keep up with it.”

The latest additions to CA’s IAM product portfolio are CA’s Federation Manager product, designed to simplify the deployment of federated partnerships, and CA’s SOA Security Manager, a policy-based administration tool that secures access to services by inspecting the content in XML messages.

“People are very immature in this space,” Hansen said. “About five or six years ago, most companies had their entire application portfolio inside their firewalls. Now, more apps are outside and everything requires a level of authentication.”

Most companies, he added, don’t have a process for how to manage security as they roll out new third-party applications and services.

Both products will be generally available next month.

Adnan Amjad, a security and privacy services partner at Deloitte, said that CA is addressing a big gap in the security market and sees a significant opportunity for the company.

“People aren’t waiting for IT anymore, they are blazing down this path to look for things quicker and cheaper,” he said. Even though other business units are commissioning these products on their own, most industry experts would agree that IT is the most likely candidate to be held responsible in the event of a data breach.

According to a recent CA sponsored survey of 555 global IT managers, 43 per cent of respondents perceive security threats, such as XML targeted attacks, as the most critical issue in the implementation of service oriented architecture (SOA) and Web-based IT apps.

CA’s CEO John Swainson said that technologies like virtualization, server SOA, social networking apps, cloud computing and networked devices, are all contributing to IT complexity.

“These six technologies will change the nature of enterprise IT for ever, and simply cannot be managed in the conventional ways,” he said. “Without a new approach to automating the IT environment, the complexity will make it impossible.”


Sign up for our Newsletters












Print |  Views: 827   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rafael Ruffolo Rafael Ruffolo was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.

Related Content

Aging firewalls pose security risks
Aging firewalls pose security risksThe succession of admins maintaining geriatric corporate firewalls often leave a trail duplicated rules and security holes that lay an organization open to various attacks
Learn when to back off
Learn when to back offBeing overly rigid on security procedures can sometimes do more harm than good. Knowing when to cut users some slack can actually help to tighten your security environment.
ID management offers more than just security
ID management offers more than just security Today’s business is a world of mobile work forces, networks and scattered places where information about employees is stored. Wouldn’t it be great to have technology that makes it easier to manage the flow of corporate information, improve the quality of data gathered by a business, and have a tighter rein on what users can do when it comes to computing?
Dan Swanson's Security Resources: #5
this week i wanted to highlight two significant security initiatives, the cert resiliency engineering research project and the cert governing for enterprise security (ges) initiative. i also wanted to point out some landmark security guidance (the ciao/iia series) with the initial "call to action" paper being released at the white house on april 17, 2000. as always, i have also included a couple

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.