SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

White House insider urges cyber-security rethink

White House insider urges cyber-security rethink

By:  Mari-Len De Guzman  On: 03 Jul 2007 For: IT World Canada Creator

Technology exists to build protection systems into IT’s infrastructure, but the biggest challenge remains the human element.

IT security is moving into the enterprise core as organizations strive to combat data breaches and other pervasive Internet threats, according to a former White House cyber-security expert.

Howard Schmidt, a former special adviser for cyberspace security to the White House, says “operationalizing” security involves making it a component of the whole enterprise architecture, as opposed to simply a plug-in component for deploying security agents such as antivirus, firewall and intrusion detection systems.

“One of the biggest things I see in the enterprise is that they’re looking to insert security as this standalone thing,” says Schmidt, who was also chief security strategist for the U.S. Computer Emergency Response Team at the Department of Homeland Security.

“They look at antivirus, anti-spyware and firewalls as almost discreet components of an enterprise.”

Schmidt, who has been traveling to various countries recently to speak on cyber-security issues, says the industry is beginning to see a shift in how enterprises are handling IT security.

Making security a part of the enterprise architecture gives the IT department a panoramic view of security as it relates to the whole enterprise, he adds.

“Many companies are realizing the benefit of having this visibility across the enterprise,” says Schmidt. “Instead of spending $10,000 to manage individual, discreet devices, by having a single platform that you’re viewing across, you get the economies of scale,”.

Schmidt likens the shift in security management to firefighting, where previously homes and office buildings were built and furnished without considering the flammability of materials used. In the olden days, as well, firefighting was a voluntary effort, he explains.

“Much of what we were doing (in the enterprise) was subject to compromise, subject to data breaches, subject to identity theft. And the way we dealt with it, at the time, was to run in there like the volunteer fire department, sort of like the technologists who have a little bit of a sensibility around security.”

The next-generation of firefighting, however, saw buildings being built with sprinkler systems, for instance, or making materials less flammable. The same shift is happening in the enterprise security arena, where it’s becoming less about how quickly an organization can respond to an incident and more about preventing breaches from happening, says Schmidt.

So, how does an organization make the shift? The first step is to identify where the risks are, says Schmidt.

“In many enterprises, the measurement of success is based on 99.999 per cent uptime. You have to look back and identify what the risks are, both internal and external, such as telecom failure, hardware failure, software failure,” he says.

Schmidt suggests looking at some standards already in place that pertain to risk mitigation and then finding those that best apply to your organization. Some of the more useful are ISO 17799, COBIT (Control Objectives for Information and Related Technology) and the National Institute of Standards and Technologies’ framework on risk management.


Sign up for our Newsletters
Tags: failure












Print |  Views: 645   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mari-Len De Guzman Mari-Len De Guzman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Federation of Security Professionals
Federation of Security ProfessionalsAs Microsoft prepares to bring its answer to Apple's popular device into Canada, security experts wonder if the music player will open up another avenue for corporate data theft. Assess the USB and DLP factors
Canadian SMBs asleep at the security wheel
Canadian SMBs asleep at the security wheelA Symantec survey finds 68 per cent of companies spend less than 10 per cent of the overall IT budget on safeguarding systems and data. And don't bother searching the CSO
Remote monitoring tool could extend control
Remote monitoring tool could extend controlNumerex’s FastTrack, which includes hosted application and GSM device, monitors processes such as temperature gauges, and could later be tied into ERP and CRM systems
Trying to Throw the Brick through the Cloud – Microsoft/Yahoo vs. Google
there has been much press and discussion about the potential merger between microsoft and yahoo (the brick) in an attempt to become a formidable force against google (the cloud).  yahoo management does not want to be taken over and they have recommended rejection of the offer, turning this into a potential hostile takeover.  the hostile takeover of y
Wireless LAN security vs. convenience - walking the tightrope
by joaquim p. menezes - “security vs. ease of use” – is a conundrum a lot of network managers face when it comes to wir
What's in store for Google's GDrive
whatever google offers with the gdrive – assuming it ever actually comes out with the gdrive – it’s got to be better than having
blog comments powered by Disqus