IBM is aggressively expanding its security portfolio in hopes of becoming the de facto source of advice and technology for businesses looking to adopt high-level IT governance and risk management strategies -- a transformation among customers that officials at Big Blue cite as both ongoing and inevitable.
As the waves of security threats and data management regulations have washed ashore and left organizations struggling to balance perimeter and internal security concerns with mounting obligations to protect highly-valuable data, companies are being forced to take more of a top-down approach that addresses broad sets of IT-oriented risks, versus individual problems, IBM officials maintain.
And while a host of players ranging from security software makers to massive IT consultants have begun marketing themselves as those best suited to help customers embrace a governance and risk management approach, IBM executives claim that their firm's mix of technology, services and partnerships place it at the top of any list of providers capable of helping organizations prepare their security operations for the future.
"We feel that we're ahead of the curve and driving forward our ability to meet these needs, some of which that might not yet have emerged from a broad perspective," said Kris Lovejoy, IBM's director of corporate security strategy.
"We feel that we are creating security risk management capabilities and have an opportunity to commoditize them in a way that can be leveraged at large," she said. "From an overall strategic perspective, that doesn't mean that customers are ready to stand up en masse right now and require everything we've built, but we're actively trying to extend the portfolio in advance of that trend."
Industry specialists, including Symantec and McAfee, the world's two largest security software makers, have also adopted high-level product and marketing efforts meant to help customers move away from battling individual threats and compliance regulations in favor of a more generic risk management strategy, but IBM claims that it is better positioned to help customers move in that direction today.
While the traditional security vendors have long been focused on shipping products that address various elements of end-to-end security and have only moved into risk management in the last two years, Big Blue has its own products and services as well as partnerships with those very vendors and many others that give it an upper hand, IBM executives said.
"In a sense, today, security is like a car without a steering wheel, and we think we're the only vendor who has the right abilities across all the involved domains that can drive change across business processes," said Eric McNeil, manager of corporate security strategy at IBM. "These other companies touch on a lot of domains, but we're the only ones who have all the pieces that span identity, applications security, physical security, and asset lifecycle management."
With its broad array of product and services skills, the executives said that IBM is best qualified to pull together key components that will allow more organizations to manage security using analytical reporting, policy creation and enforcement, and through the use of risk analysis dashboards.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »