Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

IT security and management on collision course

As security companies push into systems management, and vendors in the management space push back, convergence of the two is ongoing and largely unavoidable


"The bar for management has risen in the last few years with issues such as virtualization placing a heavier demand for coordination between security and management," Brown said. "We really needed to become a leader in both disciplines and offer a consistent fashion through which customers can manage and remediate their systems in a tightly integrated way."

Symantec has been helping companies manage compliance issues for a decade, Brown noted, but alerting customers to problems that auditors might find is no longer enough, he contends, because users are also asking the vendor to provide the mechanisms necessary to remediate any issues it finds.

Emerging technologies such as network access control (NAC) that involve everything from testing systems configuration to updating AV tools won't be as broadly adopted by end-users if vendors such as Symantec can't offer the ability to cover both the security and management tasks they require, the executive said.

Leaders of systems management companies such as LanDesk echo Symantec's observation that their products are increasingly becoming the tools through which customers handle a great deal of security work.

"Many of our customers are having a hard time differentiating between systems and security management as so much of what they do to secure the device is around traditional systems management work," said Steve Daly, who took over as general manager at LanDesk at the beginning of 2007.

"Customers are looking for tools that give them a view into inventory, the known state of their systems, to do the remediation and bring everything into compliance, which is really the traditional realm of systems management," Daly said. "They're talking about moving to service management, but the reality is that they're caught up being reactive in break-fix mode; they want to move into more of an over-arching process focus, and that's driving a philosophical change for IT and how we deliver our products."

Those factors are the very reason that a systems management specialists such as LanDesk was pushed to launch its maiden host intrusion protection system (HIPs) earlier this year, Daly said.

"Our opportunity comes from being able to lock down the device and watch the device and defend it in a preemptive manner, versus after an attack hits the device," Daly said. "I think it will be more of a challenge for the Symantecs of the world to build a single client that covers both security and management, coming from their side of the business."

Other management technology vendors said that they have long considered security as one of their core strengths, even if they didn't market their products as such.

Marty Kacin, co-founder and chief technology officer at systems management appliance vendor Kace, said that midsize companies have been approaching the issue from a more unified standpoint for years, and that enterprises are merely beginning to follow suit in viewing the issues together.

Along with covering issues of inventory and systems image provisioning, Kace's appliances provide features including security patch distribution and desktop vulnerability assessment.

"We've never differentiated security from management from the get-go, yet we never marketed around security until recently when it became clear that this was a message that resounds with customers," Kacin said. "And really when you think about it, it's not just that patching and configuration management relate to security, the issue is that the processes of systems management and security are fundamentally interdependent."

Companies such as BigFix, which has marketed itself as a security and management vendor for some time, claim that their existing business models illustrate the very approach that enterprises must take when considering the individual strategies.

"When your job is to sit on the end point and tell it how it needs to look and behave, it's clear that we're ideally suited to tackle both of these problems from a management perspective," said Greg Toto, vice president of products and operations at BigFix.

"CIOs are annoyed with the volume, complexity and integration issues driven by the use of all these security and management point products in unison," Toto said. "The value proposition of a company like ours is to provide control for a broad range of these agents via a single management console."

Matt Hines is a senior writer at InfoWorld.
« PREVIOUS PAGE | 1 | 2 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





MIGRATING TO VISTA
Join Windows Vista Expert, Richard Whitehead as he presents the benefits and challenges of migrating to Windows Vista. Sponsored by Novell

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 10/10/2008

A look back at the week: AMD splits into two, Panasonic sets world record...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist