November 27, 2006

EMC: Vendor cooperation key to data security

Harmony on security policy key to data security

The cool reception from Wall Street this summer after EMC’s announcement that it would buy RSA Security had EMC executives feeling a bit flummoxed -- like the guy who elopes, only to find out that his friends didn’t like his girlfriend to begin with.

EMC’s stock fell 3 percent following the announcement, and in talks with analysts and reporters about the $2.1 billion deal, CEO Joe Tucci faced tough questions about the price his company paid for RSA and EMC’s overall strategy . Four months later, EMC’s stock has recovered nicely, and the company is moving forward on efforts to use RSA’s assets to create a common security platform that stretches across all its products. InfoWorld Senior Editor Paul F. Roberts checked in recently with Dennis Hoffman, vice president and general manager of the Enterprise Solutions Business Unit at RSA, the Security Division of EMC, to see how things are going.

InfoWorld: You headed up EMC’s security group prior to the RSA purchase. How is your strategy different now?

Dennis Hoffman: The interesting thing is that there’s no difference in the strategy before and after. We made some broad conclusions and built a plan around that. We saw information security, as a market, colliding with information management. The only thing that took a lot of time was sorting out what were the salient parts of the information-security industry for that strategy. When we did that, we carved out what turned out to be the vast majority of the security revenues. We said, “We’re not part-interested in anti-virus, firewall, IPS, and IDS systems. That’s yesterday’s security battle.” Everyone paying attention to what’s in the news: people losing information and data breaches that are exposed in the public eye.

IW: You’ve said RSA’s technology will become a common authentication platform for EMC’s products. How far off is that vision?

DH: Those services -- authentication services, authorization services, auditing services -- are all being delivered into the base EMC platforms throughout 2007 as part of delivery of the common security platform. It will all start during the middle of next year, and it will just depend on when various releases get on the train.

IW: How do you get true security without better platform security from companies like Microsoft? How do developments in Redmond affect what EMC and RSA do?

DH: They’re certainly interrelated. In fact, I just got off the phone with the general manager of the Windows Security Business just before our call. We’re talking about ways the two companies can partner more deeply and better than we have historically. As an industry we’ve been obsessed with the idea of “perfect security” for a long time. It doesn’t exist. Perfect security is called business discontinuance. You turn off the company and then everything is secure. We’ve learned with our adaptive authentication products that as banks seek to protect the identities of their own consumers, they’ve found that the mathematically correct, rigidly correct security isn’t the right kind for them.

I don’t think that any of us in the rest of the stack -- Microsoft at the operating system level ... Cisco at the network, and EMC at the storage and information layer -- can stand and throw rocks at each other or wait for the other guy to get perfect before we can do anything.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.