Home > Security News > Beyond borders: Losing the perimeter to gain better data security
Security News:
EMAIL THIS

Beyond borders: Losing the perimeter to gain better data security

By Anne Saita, News Writer
29 Jul 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

LAS VEGAS -- Most people acknowledge that the speed of business in an increasingly interconnected, global online community can be the hobgoblin of an organization's security posture.

"Everything we do -- business, security, anything -- is now business-driven," explained Paul Simmonds, global information security director for British conglomerate ICI Plc. "Your projects have to have a return on investment. Cost savings is the management mantra. And speed to market is quite often the enemy of good security."

Then he told a packed audience at the opening of Wednesday's Black Hat Briefings: "If you haven't noticed it yet, we've lost the war on good security."

But Simmonds and a CISO-involved group he recently founded called The Jericho Group believe there's a way to return to a more secure business world by redefining which assets need corporate protections and which can move outside the perimeter and let business function with fewer impediments.

It's a concept called "de-perimeterization," a term coined by the non-profit Jericho Group to explain a worldwide push toward a more porous corporate shell yet more secure collaborations in our increasingly interconnected online world.

"Your border is actually a sieve, keeping out the lumps -- keeping out the script-kiddies," Simmonds explained. But traditional security approaches such as firewalls and intrusion detection at the network's edge are not sustainable, he continued, especially as more enterprises expand their Web services and allow every type of device to connect to their networks.

More corporations now offer non-essential external services to operate with minimal security outside their corporate networks, thereby freeing up more resources to protect other assets while letting more projects proceed at a quick pace. This, Simmonds said, is the first step toward removing a hardened perimeter.

Soon, he argued, the network border will dissolve as outside connections through partnerships, remote workers and e-commerce increase. Encryption will become paramount to protecting data in use, transit and storage.

More pie-in-the-sky is de-perimeterization's ultimate goal: worldwide use of system-, data- and connection-level authentication. Such approaches restrict access to server and data files through rights management and secure protocols. Though Simmonds admited such cross-company global authentication is beyond current capabilities, expanded use of federated identity and strides by organizations like the Liberty Alliance will make it possible.

But security still remains an individual, yet communal, responsibility.

"Ultimately, it's up to all of us … to stop designing insecure systems. It is as simple as that," he concluded. "We have to design-in security from the ground up. We can't keep papering up the cracks.

"We have to demand secure and authenticated protocols and refuse insecure protocols. You also need to understand your data flow. It is basic, but we don't do it."

Tags: Client securityNetwork Firewalls, Routers and SwitchesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Client security
DLP technology challenges security costs
Endpoint protection best practices manual: Combating issues, problems
Kaspersky update for SMBs in wake of free Microsoft Security Essentials
Microsoft makes free antivirus software widely available
Security best practices in hotels
Best Antimalware Products
Perimeter defense in the era of the perimeterless network
Microsoft Security Essentials (MSE) shows no vision, expert says
Smart tactics for antivirus and antispyware
Top tactics for endpoint security

Network Firewalls, Routers and Switches
Best Network Firewall Products
What is the difference between static and dynamic network validation?
Screencast: Smoothwall offers firewall defense in lean times
New Cisco IOS bugs pose tempting targets, says Black Hat researcher
How to implement virtual firewalls in a complex network infrastructure
How to manage network bandwidth with distributed ISP bandwidth
Firewall rule management best practices
Should enterprises be running multiple firewalls?
What are the disadvantages of proxy-based firewalls?
IT pros find corporate firewall rules tough to navigate

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
brute force cracking  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
Crash Course: Spyware  (SearchSecurity.com)
email spoofing  (SearchSecurity.com)
phishing  (SearchSecurity.com)
rootkit  (SearchMidmarketSecurity.com)
social engineering  (SearchSecurity.com)
Wired Equivalent Privacy  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts