Linux Security and Unix Security
Home > Ask the Security Experts > Platform Security Questions & Answers > Will having two different operating systems cause administrative problems?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Will having two different operating systems cause administrative problems?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 November 2006
What are the consequences if a company has one platform for application development and another for, say, infrastructure operations, like email and print functions? Will two different operating systems give rise to administrative problems?

>
EXPERT RESPONSE
There are arguments both for and against running heterogeneous networks, but the deciding factor will mostly likely be your budget. With unlimited resources, it would of course make sense to use the "best of breed" hardware and software for each service that you run on your network. For your Web site, for example, you might decide to use an Apache Web server that runs on a Linux box, while your users authenticate and access the network via a Microsoft 2003 domain server. Using the most suitable software for each service makes the overall system more robust and reliable. Many application services are designed as multi-tier systems spanning database servers, application servers, Web servers and clients. It is common for different tiers of these services to execute on servers that use different operating systems. If you use application-oriented clusters to host such applications, you can still achieve a unified view of the total application service, while making it more effective and less prone to error.

The main problem with this type of configuration, though, is that it introduces a serious amount of additional administrative overhead. Taking the example of a Linux Web server and a Windows domain, your IT department would need the skills to configure, maintain and support both Linux and Microsoft systems. You would need an increased staff in order to achieve this, obviously adding to your overall IT costs. Running a heterogeneous system will also increase the overall complexity of your network, which in turn increases the risk of errors or inadvertent data security breaches caused by the diverse systems and components.

There are other practical limitations, too. Not all software programs will be available in every OS version, so you may have to run completely different antispyware programs, for example, with each operating system. This further increases your administrative overhead. You mention using a different platform for development than for other infrastructure operations. Your development environment should certainly be kept separate from your day-to-day network operations, but by developing applications on a different platform altogether, you could end up with increased development costs and deployment issues.

More information:

  • Learn why Web services security should begin at the application level.
  • Read how hackers can access machines by attacking an operating system.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Platform Security
    Is attack code valuable for vulnerabilities or just a publicity stunt?
    Will the features of Windows Vista SP1 encourage wider adoption of the OS?
    Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
    Are open recursive DNS servers inherently insecure?
    Should whole disk encryption products be used with data backup software?
    Which operating system can best secure an FTP site?
    Is desktop virtualization a realistic enterprise option?
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?

    Web Services Security and SOA Security
    Information security book excerpts and reviews
    Kaminsky on DNS rebinding attacks, hacking techniques
    Which operating system can best secure an FTP site?
    IBM's Watchfire halts network research, focuses on Web apps
    How does identity propagation work?
    Citrix adds Web security with acquisition
    Are attackers using malware to exploit service oriented architectures?
    Using an XML security gateway in a service-oriented architecture
    Web security gateways meet rising malware threats
    SOA, Web services security gaining priority at large enterprises

    Linux Security and Unix Security
    RE:trace framework aids in OS X, Unix flaw discovery
    Researcher behind Linux Kernel flaw explains motives
    Linux Kernel attack code worries security experts
    Mac hack puts Apple faithful on the defense
    Linux patch problems: Your distro may vary
    What is the best antivirus software to use when running Linux?
    Security Bytes: Crossover platform virus on the loose
    Security Wire Weekly: New Linux worm, J-Lo's high risk CDs and how an adware firm atones
    RSA Conference 2006
    Securing Web logins

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    trusted computing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts