|
Visit Our E2 Forums |
Education |
Financial Services |
Government |
Healthcare |
Manufacturing |
Retail
New! Focus on: End User Computing
|
||||||
More Than Malware: A Holistic Approach to SecurityCormac Foster, Journalist, Analyst, Tech Manager | 1/22/2013 |
Malware is going to be ugly in 2013. BitDefender is already calling this "The Year of Mobile Malware," which should send shivers down the spines of anyone playing with BYOD. In addition to all the usual PC-based viruses and Trojans, IT now has to add rogue cellphones and tablets from the unprotected wild to its list of threats. Device-level anti-malware is more important than ever. Still, it's easy to get too wrapped up in end-point anti-malware at the expense of your broader network protection strategy. Two recent Gartner blogs have pointed out very different vulnerabilities that are equally important, and a good security system needs to address them all. In Playing Chess with APTs, Gartner's Dan Blum argues that fortifying firewalls and locking down end points are noble goals, but by themselves, they provide an outdated and insufficient security design. To Blum, the enterprise needs to extend its reach beyond the firewall through Secure Web and Email Gateways, while simultaneously developing internal procedures for sensing, analyzing, and sharing data about threats that do make it past the perimeter. Blum raises excellent points. Attackers' tactics evolve daily, and the volume and types of network traffic passing through networks grow every year, yet our moat-and-castle defenses haven't changed in two decades. Spreading your security footprint and gathering intelligence quickly are the new keys to survival. Blum told me more in an email exchange:
Companies should develop operational efficiency on stopping malware. This means not only deploying state of the art protection tools, but also employing change management, virtual re-imaging and integrity monitoring technologies to bulletproof the critical data center environment. But even with that, assume that sophisticated and persistent groups of adversaries can reconnoiter and work around any static defense. If your organization is thought to be at heightened risk of targeted attacks, also deploy advanced security monitoring tools and subscribe to threat intelligence services. Malware isn't your only risk, and it might not be the biggest. In More on Internal Data Loss Incidents, Anton Chuvakin cautions against sloppy policies that could (and probably will) cause more damage than any super-virus. Even the most hardened perimeter is useless if everything on the inside is wide open. The highest-profile hack of this century was allegedly conducted by a single man with a recordable CD. According to charges filed by the US government, Private First Class Bradley Manning downloaded hundreds of thousands of sensitive and classified files and cables. How was an enlisted soldier able to access that much data? Poor planning and lazy design. Any system that allows partners and employees free reign is a lost cause long before the malware arrives. Social engineering, spear-phishing, physical device theft, and other non-malware attacks can bypass even the strongest external barriers, and businesses need to be able to identify and contain threats when they arise. Malware is important, and building a strong fence against it is critical, but every fence has holes. To be effective, your business needs a holistic security policy that does what it can to minimize intrusions, locks down intruders when they get through the gates, and provides the information you need to shut down the threat as quickly as possible. The blogs and comments posted on EnterpriseEfficiency.com do not reflect the views of TechWeb, EnterpriseEfficiency.com, or its sponsors. EnterpriseEfficiency.com, TechWeb, and its sponsors do not assume responsibility for any comments, claims, or opinions made by authors and bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose. |
More Blogs from Cormac Foster
Cormac Foster 1/25/2013
This is supposed to be a big year for identity management. IDC thinks we might all be logging onto the corporate network with our Facebook logins. Wired Magazine has declared passwords ...
Cormac Foster 1/16/2013
CIOs and other IT leaders are increasingly being asked to work with colleagues across the organization to develop ways to mine structured and unstructured data in order to draw actionable ...
Cormac Foster 1/8/2013
The last time we touched on software defined networking (SDN), or virtual networking, the industry was just lining up behind the OpenFlow standard that now defines it. By the end of 2012, ...
Cormac Foster 6/22/2011
What do ISO 9001, HIPAA, PCI, Sarbanes Oxley, and a weekly drop-ship of 25 teddy bears to Des Moines every Tuesday have in common? They're all promises to do a certain thing a certain way ...
Latest Archived Broadcast
Data visualization can make complex data easier to grasp. Our expert guest will talk about the hows, whys, and whats of bringing the big picture to your enterprise.
On-demand Video with Chat
NBA CIO Michael Gliedman will tell us why the NBA decided to create NBA.com/stats
6/18/2013 -
Please join us for the "IT Convergence Strategies: Why, When and How " to learn more about:
• 5 truths about infrastructure convergence today that go beyond the hype
• How to exploit the 4 phases of convergence maximum efficiency and agility
• Key milestones to plan for on the convergence journey
• Why integrated management is a critical component of convergence plans
• The importance of an open, modular approach, such as Dell’s active infrastructure, to building a converged data center
E2 IT Migration Zones
Office 365 Finds Fans
Cutting Through the Modern App Confusion
Microsoft Hints at Changes to Windows 8
S’équiper ou non d’un logiciel anti-virus ?
Microsoft passe au facteur deux
Windows Azure Infrastructure Services est disponible !
Microsofts Surface Pro kommt nach Deutschland
Zum Schmunzeln: drei neue Werbeclips für Windows 8
Like Us on Facebook
Dell IT Insights
![]() ![]() Site Moderators Wanted
Enterprise Efficiency is looking for engaged readers to moderate the message boards on this site. Engage in high-IQ conversations with IT industry leaders; earn kudos and perks. Interested? E-mail:
moderators@enterpriseefficiency.com The major problem facing the CIO is how to measure the effectiveness of the IT department. Learn how Dell’s Efficiency Modeling Tool gives the CIO two clear, powerful numbers: Efficiency Quotient and Impact Quotient. These numbers can be transforma¬tive not only to the department, but to the entire enterprise. Read the full report Virtualization is a presence in nearly all enterprise data centers. But not all companies are using it to its best effect. Learn the common characteristics of success, what barriers companies face, and how to get the most from your efforts. Read the full report Cut through the VDI hype and get the full picture -- including ROI and the impact on your Data Center -- to make an informed decision about your virtual desktop infrastructure deployments. Read the full report SPONSORED BY DELL
BRIEFINGS
CASE STUDIES
EBOOKS
PUBLIC SECTOR RESOURCES
VIDEOS
WHITE PAPERS
A Video Case Study – Translational Genomics Research Institute e2 Video
|
|||||
|
|
||||||