July 31, 2008

Symantec: New attitude on security needed

Customers have to focus on protecting the information, not just the PC or the network, advises Symantec chairman/CEO

Government agencies and private companies need to move their focus away from single-point security solutions to more holistic, information-based security, Symantec officials advised.

"Clearly we've moved to a point in time where our customers have to be much more focused on protecting the information itself, as opposed to protecting the PC or protecting the network," John Thompson, Symantec's chairman and CEO, said Thursday at the company's government symposium in Washington, D.C. "While those are necessary components of a protection strategy, they're not the end all. More has to be done."

[ Your source for the latest in government IT news and issues: Subscribe to InfoWorld's Government IT newsletter. ]

In recent years, U.S. lawmakers have focused their attention on data breaches and lost laptops, and federal agencies have scrambled to meet requirements for encrypting information on laptops and other mobile devices. On Monday, the U.S. Government Accountability Office released a report saying that only 30 percent of sensitive data on mobile devices at 24 major agencies had been encrypted as of last September.

Encryption can be an important piece of a cybersecurity strategy, but it's just one piece, Thompson and John McCumber, Symantec's strategic programs manager for the federal public sector, said in interviews Thursday.

Encryption isn't "the solution" to data-loss prevention, Thompson said. "Good data-loss policies start with the understanding of, what is the critical data that I have and where is it?" he said. "In many instances, there is some critical and sensitive information on every laptop. But not all information that's on that laptop is critical and sensitive."

McCumber recently had lunch with a member of the U.S. Congress who suggested that better encryption technology would solve the government's data-loss problems. But McCumber told the lawmaker that encryption can't protect data that's being processed.

"If you think cryptography is the solution to this problem, you don't understand the problem and you don't understand cryptography," said McCumber, a former encryption expert at the U.S. National Security Agency.

Instead of focusing on single-point security solutions, Symantec has been encouraging U.S. agencies to look at the information they hold. The security vendor recommends agencies create "thoughtful" data classification and retention policies, Thompson said. Such policies will make it easier to manage and find data in the long term, he said.

"You've got to look at what value you place on the information," added McCumber. "Nobody wants to pay $500 to protect a $50 asset."

Agencies looking at cybersecurity from that information-centric perspective may find that adopting industry best practices -- what other agencies or private companies are doing -- may not work for them, McCumber said. Each organization needs to look at its own security challenges and risk, and find a data protection plan that works best for it, he said.

Organizations need tools to understand and manage their risks, McCumber added.

If best practices aren't the answer, that means technology mandates from Congress or regulatory agencies will no longer work, he said. "Technology always changes," McCumber said. "They've had to learn the hard way. You can't solve technology problems with policies, and you can't solve policy problems with technology."

Correction: Due to a reporting error, this story as originally posted included an incorrect quote from Symantec official John McCumber. The article has been amended.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.