SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Would you hire Dubai to run your infrastructure?

Would you hire Dubai to run your infrastructure?

By:  Winn Schwartau  On: 30 Mar 2006 For: ComputerWorld Canada Creator

The issue was not political, at least not in my mind. It was all about security. In the national hoopla over whether a foreign government or those under its control should run operations at major U.S. ports, I heard lots of misplaced xenophobia. I wanted to understand the security implications as they might apply to networks in a similar situation, and that took me back to 1999.

The issue was not political, at least not in my mind. It was all about security. In the national hoopla over whether a foreign government or those under its control should run operations at major U.S. ports, I heard lots of misplaced xenophobia. I wanted to understand the security implications as they might apply to networks in a similar situation, and that took me back to 1999.

At a classified counterterrorism briefing, speaking to a room full of Pentagon brass, I opened with, “Generals, you have lost command authority of your armies.”

I described the implications of the military using foreign nationals to operate unclassified aspects of their global networks. The idea had been that using local individuals in overseas bases was good politics, and because the networks and information were all unclassified, what’s the harm?

The first harm is that unclassified networks that supply meals and travel orders, for example, support military readiness. That is why U-boats targeted the shipping lanes during the Battle of the Atlantic. A severe compromise of a portion of unclassified networks could be just as devastating as a breach of classified security. The Pentagon got the message and the policy was changed quickly.

The second harm is that if you take a bunch of unclassified data and piece it together in the right way, like a jigsaw puzzle, the resulting information could be immensely valuable to a potential adversary. This is why so many organizations are sensitive to dumpster diving and other techniques that can divulge seemingly innocuous information to the public domain. Most of us try to protect company phone books, employee rosters and so on.

The question is, how much of your infrastructure operations and security-relevant processes do you want to outsource? While thinking about the United Arab Emirates/Dubai national security parallel and the natural follow-up — “Is our network protection any less important?” — these questions come to mind:

• Do you want to outsource any of your critical IT operations? If so, how do you make the distinction between mission-critical and non-critical day-to-day operations?

• If you outsource, how quickly can you bring full operations back to an internal function?

• How much of your security do you want to outsource? For example, is perimeter access-control administration better done internally or handed over to outsiders? How many layers of security administration do you have and do you want, and where are they located physically?

• How much of your physical access control, administration of badges and ID tokens, and border security of your facilities do you feel comfortable outsourcing?

• If you choose to outsource, how can you oversee the quality and trustworthiness of those hired to manage your security-relevant assets? A background check can determine only if someone has already been caught. If you outsource to a foreign company, does that make employee oversight more difficult?


Sign up for our Newsletters












Print |  Views: 523   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Winn Schwartau Winn Schwartau is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Cyber criminals breach US electrical grid
Cyber criminals breach US electrical gridIntrusions by cyber spies from China, Russia and elsewhere are pervasive, according to government officials
Canadian companies must 'urgently address' security skills gap
Canadian companies must 'urgently address' security skills gap Nearly half of all companies here experiencing security breaches over the past five years, according to a recent survey
Crosscheck Networks targets developers with SOA testing tool
development teams implementing soa (services-oriented architecture) can quickly test the quality of their enterprise wsdls using a scoring system, the boston, mass.-based vendor said.crosscheck networks inc. released version 4.0 of soapsonar, which provides developers a feedback loop to help improve quality of wsdls and, in turn, increase inte
blog comments powered by Disqus