Home > Security News > Growing demand for command-control services
Security News:
EMAIL THIS

Growing demand for command-control services

By Bill Brenner, News Writer
24 Nov 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Enterprises once limited security budgets to antivirus software and firewalls. Then laws like HIPAA and Sarbanes-Oxley prompted them to invest in broader defenses. If a new Yankee Group study is any indication, compliance concerns are paying off for vendors that offer command and control services.

"We're seeing something equally as important as threat mitigation, and that's command and control," said Phebe Waterfield, an analyst for the Boston-based research firm. "Regulation is the main driver. Companies are being held accountable for their security, and with accountability comes the need for a more mature process."

Waterfield reached that conclusion after talking to representatives from 606 enterprises about their security budgets over the past year. She said a variety of people were interviewed, including chief financial officers and chief security officers. "The respondents all had input into how their company's security dollars are spent," she said.

While threat mitigation has been the chief concern of enterprises in recent years, Waterfield said the trend is shifting in favor of command and control companies. "That's the biggest growth area," she said. "When we think security, we tend to think of threats and how to mitigate them. That's not really the goal, to avoid every threat out there. The goal is to have IT systems that are managed in a way that makes them consistently safe, especially if your networks house sensitive financial or health information."

The study predicts the global security market will generate $12.9 billion in revenue for 2004. Waterfield broke the security market into three components:

  • Threat mitigation, layered defenses against worms, viruses, denial-of-service attacks, intrusions and buffer overflows. "The threat mitigation segments are perimeter firewalls, network integrity systems, application gateways and system integrity software," Waterfield said. "This component represents 42% of the security market and is estimated at $5.4 billion in 2004."
  • Command and control, solutions for managing network security, representing 40% of the security market with an estimated $5.2 billion in revenue for 2004. "Command and control includes identity management, security event management, vulnerability assessments and patching, and intrusion detection audits," Waterfield said. While threat mitigation services have generated more revenue and a larger market share this year, Waterfield said command and control services have shown the most growth and the feedback she received indicates the trend will continue.
  • Managed security services, the use of external expertise in operating and improving the performance of security processes. "Managed security services represent 18% of the security market and are estimated at $2.3 billion in 2004. This component includes augmenting in-house operational staff, enhancing security response, reducing operational expenses and improving the security process and strategy," Waterfield said.

She said Cisco Systems, Symantec and VeriSign have shifted a lot of emphasis to command and control services and have emerged as market leaders.

"Cisco Systems is adept at delivering security as an end-to-end network service. Its vision of a self-defending network, including network admission control, is resonating with large enterprises," Waterfield said.

She said Symantec was rated the most trusted security vendor for both products and services in Yankee Group's 2004 surveys. "Its leadership in desktop software and in fighting threats at all layers of an integrated defense sets a high standard for the industry," Waterfield said.

VeriSign, known for digital identities that drive secure communications on the Web, has been building an impressive global managed services business, she said. "The company has security in its pedigree and the capital to sustain a strong business," she said.

Tags: Gramm-Leach-Bliley Act (GLBA)HIPAASarbanes-Oxley ActIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Gramm-Leach-Bliley Act (GLBA)
Implement security and compliance in a risk management context
The road to compliance
IBM to boost security spending, push PCI DSS program
ISO 27001 could bridge the regulatory divide, expert says
Policies and regulatory compliance
Where hard drives go to die, or do they?
Compliance guide for managers: Lessons learned and best decisions
Become compliant -- without breaking the bank
Compliance Guide for Managers
Making sense of the maze
Gramm-Leach-Bliley Act (GLBA) Research

HIPAA
Cost of security, IT management add up at healthcare facilities, study finds
Healthcare security spending remains sluggish, report shows
Creating a HIPAA employee training program
FTC extends breach notification to Web-based health repositories
Are there guidelines to create a HIPAA-compliant data center?
HHS HIPAA guidance on encryption requirements and data destruction
Writing a patient identifier policy to prevent common HIPAA violations
HIPAA compliance: New regulations change the game
HIPAA compliance manual: Training, audit and requirement checklist
Key elements of a HIPAA compliance checklist
HIPAA Research

Sarbanes-Oxley Act
SOX compliance burdens midmarket security teams
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Does password sharing in international branches violate SOX?
Consensus Controls project aims to set benchmarks for compliance
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
Sarbanes-Oxley Act Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts