Home > Security Tips > Network Security Tactics > Reasons why enterprise networking and security roles must stay separate
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Reasons why enterprise networking and security roles must stay separate


Shon Harris
01.16.2007
Rating: -3.94- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


If you're in charge of installing, configuring and maintaining network resources, it may be unclear where your responsibilities end. Can capable network managers, for example, stretch their duties into the security space, perhaps acting more like a chief security officer? In this tip from our Ask the Experts section, contributor Shon Harris explains how keeping security and networking functions separate can benefit an organization.

Smaller companies cannot afford to separate network and security obligations, but if your company has a large enough staff to split up networking, lab and security functions, then do not share duties. There needs to be a clear delineation between networking and security because the groups' focuses and goals are different. Networking's responsibilities mainly involve keeping resources up and available. Security is about protection, and compared to networking, this is sometimes considered a less important business priority.

More information

Learn the best options for handling segregation of duties.

Have a security management question? Ask Shon for help.
Not only should the networking group and security group have distinct and clearly defined tasks and responsibilities, but they should also have separate chains of command. The security group should not report to the networking group (i.e. network administrator or chief information officer). Many companies do have their security departments reporting to the CIO, but this is only because they do not have a chief security officer (CSO). Problems can occur when sharing the same chain of command. For instance, let's say someone in security informs a network administrator that there is an unsafe rule set on the firewall. This traffic setting, though, may have been implemented by the network administrator to support a business need or a user's particular preference. There is a chance then that the administrator may rank the network concerns more of a priority than the security issue and ignore the information.

Simply put, the networking group should maintain and configure network devices, and the security group should maintain and configure security devices.

A security officer can delegate some tasks, but this is often done incorrectly. The process is usually sloppy, and clear lines of responsibility are frequently not laid out. If a security officer delegates some security tasks to another individual, the decision should be approved by someone in a higher position, and the change in responsibilities should be documented.

Now, your arrangement of responsibilities depends on what type of company you are working in. In a privately held company, there will not be any auditors or regulators forcing your company to do the right thing. If your company is privately held, it should still follow the best practices that I stated earlier. That way, the company is more protected and better able to mitigate potential fraudulent activities.

If your company is publicly traded, auditors (internal and external) will be detecting whether segregation of duties are in place and whether boundaries are being crossed. If the company is publicly traded, compliance with SOX or the Gramm-Leach-Bliley Act (GLBA) is important to the CEO, CFO and other security officers.

The network lab manager and the CSO should perform their duties separately. If the CSO needs help, then a security engineer should be hired to properly arrange the responsibilities.

About the author:
Shon Harris is a CISSP, MCSE and President of Logical Security, a firm specializing in security educational and training tools. Shon is a former engineer in the Air Force's Information Warfare unit, a security consultant and an author. She has authored two best selling CISSP books, including CISSP All-in-One Exam Guide, and was a contributing author to the book Hacker's Challenge. Shon is also the co-author of Gray Hat Hacking: The Ethical Hacker's Handbook.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Security Event Management,   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Information Security Incident Response,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network Security Tactics
Screencast: Find rogue wireless acess points with Vistumbler
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Network access control technology: Over-hyped or underused?

Security Event Management
Network traffic collection, analysis helps prevent data breaches
Best Security Information and Event Management Products
Understanding PCI DSS compliance requirements for log management
Data breach notification legislation: What info must be released?
How to prevent a denial-of-service (DoS) attack
Mature SIMs do more than log aggregation and correlation
The top 5 network security practices
SIMs tools and tactics for business intelligence
SIEM: Not for small business, nor the faint of heart
Should IDS and SIM/SEM/SIEM be used for network intrusion monitoring?

Information Security Incident Response
Data breach notification legislation: What info must be released?
Incident response planning
Mature SIMs do more than log aggregation and correlation
New partnerships, creative thinking help security bust recession
Senators hear call for federal cybersecurity restructuring
Tying log management and identity management shortens incident response
Tabletop exercises sharpen security and business continuity
Security incident response 101
Firms muddle security breach response, expert says
Microsoft Conficker worm offers attack prevention lesson
Information Security Incident Response Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
security information management (SIM)  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts