Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register
SECURITY ADVISER  

The evolution of corporate security

As companies balance ease-of-use with security, they move up the steps of Grimes’ Hierarchy of Security Needs

By Roger A. Grimes
August 04, 2006
 

Most security solutions are a trade-off of ease-of-use versus security. As computer security measures grow in importance, previously uninterrupted legitimate processes get reined in or stopped altogether -- like my recommendation of not allowing non-admin users to install software without management approval. As companies grow more valuable, they are willing to accept higher levels of default security as measured against legitimate needs.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

In my experience, most companies’ position on computer security goes through a series of evolving steps that I can only equate to Maslow’s Hierarchy of Needs from basic safety to self-actualization. All IT processes go through this sort of trending, truth be told.

A related example is how a company ends up forming a help desk team. When the company is small, it has just one IT person. As it grows, another person or two is added. Usually at this stage, employees know to contact the first IT guy (the IT manager), who triages the call and assigns it to a team member. As the company grows, more IT employees join the department.

Pretty soon, the company’s employees have each of the IT members' personal cell phone numbers (used to be pagers) and call them at will. Each IT employee is running off here and there based upon the whims of the employees, with little thought to efficiency.

Eventually, somebody figures that all the incoming calls should go to a common number so a triage decision can be made, and a centralized help desk is born. A little thought and planning ends up saving the company time and money, and makes the help function more efficient.

The same thing happens in computer security. Some companies, like a law office I visited last week, don’t have a clue. They are running a workgroup network full of Windows 95 computers with no log-ons, no anti-virus, no patches, and no firewall. Clearly a disaster already in progress.

But to be frank, that company and others like it aren’t ready to listen to my spiel about all the current security risks and how I’m going to make their network perfect. It was all I could do to convince them that it would be nice if a law office holding lots of confidential client information required log-ons to get access to internal data and installed an Internet firewall.

And that's where Grimes’ Hierarchy of Security Needs comes into play. Whenever I enter a company for the first time, I quickly try to measure its computer security maturity. Often I can do this in a few minutes. Mentally, I’ve classified them into five stages, much like Maslow’s Hierarchy of Needs, based on their approach to security.

Stage one

In Stage One, no one thinks about computer security at all. Passwords are short and shared log-ons are common, no firewalls are installed, and the only anti-virus software they have came preinstalled on some new machines (and hasn’t been updated since). Nothing is encrypted or authenticated. Infected and compromised machines are so common that most employees keep using them even when they know they have problems.

Eventually the e-mail worm outbreaks come back-to-back, compromised systems are discovered, and machines are constantly down or slow because of malware attacks. One day a big security event happens, a client or management gets really upset, and both IT and management wake up to the problem.

Stage two

In Stage Two, management and IT agree to get more serious about computer security. Anti-virus software is purchased for e-mail servers or installed on user desktops. A network firewall is installed (but with an allow-by-default rule set), password lengths increase, and end-users are educated about the most common threats. An existing employee is told they are in charge of security, but in reality they have little to no authority and their major job task is assigning and removing passwords to multiple systems.

Management thinks it has addressed the problem. Worm and spyware outbreaks happen less often, but the entire system still goes down a few times a year. If a major worm or virus gets announced in the media, it always hits the company badly. Another major security event happens, just as bad as the first one. Things aren’t fine.

Stage three

This is the first step into what I think is a real security environment. A real security officer, with a security certification or training, is hired or created. All employees sign an acceptable use policy when they are hired, and passwords get longer and are required to be changed at least twice a year. There's a focus on automating computer security. Anti-virus software is installed on all desktops and automatically updated from location-specific servers, patch management software is utilized, and additional scanning programs to find malicious software are set up.

Viruses and spyware are finally under control. External threats are minimized. Then an employee is caught hacking the system and an IT manager is caught reading management’s e-mails. Internal threats become a very real problem.

Stage four

Management tells HR and IT to work on computer security policy, and to penalize employees who fail to follow proper guidelines. Some sort of industry guideline or legal compliance legislation (HIPAA, SOX, GBL, and others) kicks in, adding to company security policy. Passwords are complex and changed once a quarter. Dangerous e-mail attachments are blocked at the gateway.

External consultants are frequently hired. IT is interested in buying IDS, IPS, and other cutting edge technologies that promise the world but always under-deliver. The security team is actually brought in at the beginning of projects, and software developers are trained in secure coding.

Security is being considered by all members of the IT team, and management fully backs the IT manager and the security officer on all major decisions. The oversight audit team works in conjunction with IT security to perform internal audits and prepare for external assessments.

Still, some security events happen. Some employees are still opening every file attachment no matter how many times you educate them. Eventually, a confidential database is breached from the outside, and tracked to a compromised internal employee’s computer. All they did was install the latest cool thing off the Internet.

Stage five

Self-actualization. The security team and management finally understand that allow-by-default and deny-by-exception policies will never work. Strict computer policies are enacted, end-user desktops locked down, and deny-by-default polices implemented everywhere. Corporate computer images are the only ones allowed on the network. Employees caught trying to circumvent security policy are fired.

Patches are thoroughly tested and deployed according to a criticality rating. Vendor software must meet certain security requirements before it can even be considered for purchase. All confidential data is encrypted by default. Laptops and PDAs must have bootup passwords and data encryption. Authentication is built into corporate logons, e-mail, and physical security.

Finally, both internal and external threats are minimized or nonexistent. The latest computer threat is only read about, not experienced.

The scenarios and steps in each stage of the Grimes’ Hierarchy of Security Needs are only examples. The main point is that all companies have some level of security maturity. All start from the beginning and move on to stricter phases, requiring more control and less freedom; internal and external influences drive the process. Where is your company?





 


 
InfoWorld Test Center Contributing Editor Roger A. Grimes is a Foundstone Ultimate Hacking instructor/consultant teaching Windows, Linux, Unix, and Solaris security.

  More of Roger A. Grimes' column

Newsletter Check out all of our free newsletters!
Enter e-mail address:




 

TOP NEWS:


»  Top 10: Intel antitrust redux, AMD change, network woes
This week's roundup of the top tech news stories includes Intel's EC woes, AMD's new CEO, San Francisco's network issues, the ongoing MS-Yahoo saga, and more

»  Why San Francisco's network admin went rogue
An inside source reveals details of missteps and misunderstandings in the curious case of Terry Childs, network kidnapper

»  AMD takes on Intel with its own low-power chip
The chip, code-named Bobcat, is designed for low-cost laptops and mobile devices and will compete with Intel's Atom processor

»  Hold off on WiMax investments, Gartner cautions
Analysts say businesses should wait until WiMax is more widely deployed and there are more dual-mode handsets

»  Samsung, Sun jointly develop NAND flash memory chip
The 8GB single-level cell NAND flash memory chip developed by Samsung and Sun should have a significantly longer lifespan than current flash memory

»  RIM fixes critical BlackBerry Enterprise Server bug
Research in Motion patched a critical bug in its BlackBerry Enterprise Server that could have allowed hackers to break into company networks




5 Things You Need to Know About Storage Virtualization
This Webcast feature insights from various InfoWorld articles, as well as primary research conducted by InfoWorld and sister company IDC to better understand demand drivers, challenges and opportunities provided by storage virtualization, as well as other flavors or approaches to virtualization Sponsor: HP

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist