About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld InfoWorld HomeTechnology NewsTechnology Test CenterOpinionsTechnology Product GuideTechnology IndexCareers
PRODUCT REVIEWS GUIDE    REVIEWS    ANALYSES    SPECIAL REPORTS 
SiteIT Product Guide Search
 
Free Technology Newsletters
» All 33 InfoWorld Newsletters
Technology & Business Daily
 

Threat landscape and lapses justify security paranoia

Gadgets abounded in 2005; common sense remained AWOL for some

By P.J. Connolly
January 02, 2006
E-mailE-mail  

Security remained foremost on the minds of IT leadership in 2005, and with good reason. The year saw a Microsoft research project discover the first so-called zero-day exploit; "identity theft," "phishing," and "spyware" became part of the popular lexicon; and the need grew for companies to treat any computer joining the network as hostile until proved secure. It's no wonder IT people at all levels sound paranoid.

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

Return to special report

DOWNLOAD PDF

Click here to download InfoWorld's special report 2006 Technology of the Year Awards


Incredibly, the year passed without a crippling event of global reach -- although if one belongs to the glass-half-empty school, that bit of good luck can be interpreted as having simply prompted people to become complacent. After all, 2005 was a year in which some business, university, or government entity acknowledging that it had mishandled sensitive data seemed to be a weekly occurrence.

Network access control continues to be a hot marketing point, although vendors are taking myriad approaches to the subject. End-point security and device-based access controls appear to be the methods of choice, both for established vendors, including Juniper and Symantec -- which bought Funk Software and Sygate, respectively -- and relative newcomers such as ConSentry Networks, Elemental Security, and LockDown Networks. The ConSentry and Elemental solutions were the most promising we saw during the year, but the competition should be heavy in 2006.

The appliance approach to security management built some steam this year as well, with firewall vendors now offering IPS features and IPS

Click for larger view.
boxes behaving more like firewalls and routers. This method seems to appeal most in situations where network operations and the security team overlap substantially; where a strict delineation between the groups exists and all-in-one boxes are often considered a liability -- or at least an audit point -- instead of an asset. Even when they're described as "unified threat management," some IT organizations still don't trust them.

But network management and security will continue to overlap in 2006; particularly given the jerry-built nature of many smaller corporate networks. Consolidating threat management and network usage policy enforcement into one device makes sense for shops that invested in a high-quality network infrastructure that adapts easily to the new requirements; those IT organizations that built their networks on the cheap will be shut out of this brave new world.

Mind-set will remain one of the biggest problems to implementing a sensible security strategy: Most customers still make their security purchases from a tactical perspective, in effect using Band-Aids where reconstructive surgery is more appropriate. But that's all the budget can afford in too many cases.

Of course, all the gadgets in the world are pointless when basic security procedures aren't enforced or don't exist in the first place. Look at what happened this year: Unwiped hard drives with bank records showed up on auction blocks and backup tapes containing unencrypted personnel data went missing from the van transporting them. Moreover, the best place to look for a sensitive password continues to be a Post-It note. In many ways, it's as if the last decade of "there but for the grace of God go I" security breaches never happened. CTOs need to ask themselves: When the basics are so difficult, do all of the gadgets become money down the drain?




E-mailE-mail  


 
P.J. Connolly is a senior contributing editor to the InfoWorld Test Center.
 


TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




THE TOP THREE WAYS TO CUT COSTS IN 2009
With the current economic environment, organizations are looking for ways to cut costs. With Oracle Content Management, you can cut costs in three ways in 2009: consolidation, process automation and compliance. Learn more from this webcast sponsored by Oracle.

»  Click here to view this Webcast
  Enterprise Data Security Solutions Guide
Data security used to be about outside threats. These days the biggest challenge for data-driven organizations is the management of secure information from the inside out. Data is available on laptops, your network and even USB devices, but not always secure. Read this Solutions Guide to learn the best ways to keep it safe. Sponsored by ISC2

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
SEE ALSO

TAGS:

IPS  NAC  security  spyware  viruses  worms 
» COMPLETE LIST OF TAGS

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE

RESOURCE CENTERadvertisement 

Ads by techwords beta


See your link here



TECHNOLOGY INDEX

TECH WATCH 


Google Desktop out of beta
Version 4 of Google Desktop is out, but more noteworthy with the news is that it is out of beta. "We're post-beta!", Google writes. That gold feeling is lost quickly with the news that follows in the same paragraph: "Plus there are now beta ...

Will open sourcing of Java cause its forking?
Sun Microsystems looks like it will be open sourcing the Java programming language in just a few more months. The company apparently is ironing out issues with maintaining compatability in Java and ensuring no single company develops its own ...

JON UDELL'S CORNER 


Jon Udell's Column and Blog Franchising the energy web
(InfoWorld) - I’m already so depressed about the sorry state of our planet’s energy systems that I’m afraid...

Jon's Blog | Jon's Column

COLUMNISTS

Can a federation tackle the data management puzzle?
Mario Apicella's Column and Blog (InfoWorld) - I could probably fill up my column just reporting on who's buying whom -- or who's...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Open Source community subversion as marketing ploy
The launch of Microsoft's Codeplex "shared source" site is merely the latest attempt to undermine and usurp the open ...

IT Troubleshooter 
Man-Made Security Woes
In enterprise IT, all sorts of suffering happens in the good name of security. As an end user, it's really hard to know ...




IDG ENTERPRISE NETWORK
More Desktops News...  (ComputerWorld)
Juniper enhances routers for IP TV  (ComputerWorld)

GOVERNMENT IT & POLICY
Work on '07 Pay Raises May Come Later Rather Than Sooner
FCC Head 'in Bed' With Business in Magazine Spread
Officials Defend Financial Searches

ADVERTISEMENT


Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2009, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity