Home > Security Tips > Network Security Tactics > Aligning network security with business priorities
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Aligning network security with business priorities


Mike Chapple, Contributor
10.05.2009
Rating: -4.50- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Network security experts know that executives expect them to be familiar with firewall rulesets and capable of spotting potential network intrusions. What fewer of them realize, however, is that the network, like the rest of the organization, must be aligned with the enterprise's business priorities. This tip will discuss ways to align the day-to-day network security operations of an organization with its business problems and priorities.

How to frame a security budget request
The easiest way to align network security plans and practices with the business requirements of your organization is to frame network security budget requests correctly. This requires a team that is familiar with both security requirements and the business itself.

Allow me to illustrate this with an example: Joe is a security administrator who strongly feels the installation of an intrusion prevention system (IPS) on the corporate network would reduce the risk of successful attacks. Joe must make the case to Mary, the CIO, who would approve the security budget request. Mary is a seasoned CIO with an MBA who came up through the ranks of application development to reach the corner office. Joe walks in for his meeting and says: "Mary, we're receiving an unprecedented number of HTTP port scanning reconnaissance attacks through our perimeter firewall. Recent news indicates that SQL injection attacks are on the rise and I believe these attackers are performing reconnaissance in an attempt to identify database vulnerabilities. We need to buy an intrusion prevention system to mitigate this risk." How well do you think Joe did in his meeting? More than likely, both Joe and Mary left that meeting frustrated: Mary didn't understand what Joe was talking about and Joe didn't get his budget request.

Now, imagine a slightly different scenario. Joe has done an analysis of the business requirements and framed his questions correctly before making his budget r...



equest. This time, he walks into Mary's office and says: "Mary, as you know, our organization does quite a bit of credit card processing. We have a database that stores this information and I'm worried that it might be vulnerable to attack. We've seen signs that attackers from Asia are trying to identify vulnerable Web applications that might give them a path to our credit card data, and I think we need to block these attacks. The system we need to do so costs $50,000, but it reduces our exposure to attacks on our credit card data. If such an attack were successful, we'd have a major reputational problem on our hands, and we'd also be subject to fines that could range into the millions of dollars."

This approach appeals to Mary's business sense and frames the request in terms of the needs of the business. This time, Joe walks away with an approved budget request and both Joe and Mary sleep well with the knowledge that their significant investment is serving to protect them against a clear risk.

Allocating time and resources
In addition to using business requirements to frame requests, you should also use them to help allocate the limited time and resources available to you. This can be a simple cost/benefit calculation exercise that helps you decide which projects and maintenance tasks take priority. Again, let's consider an example:

Joe holds a weekly staff meeting with his four security engineers, and they're debating which of two projects should take priority:

  • Installation of firewalls at remote offices that will allow the field sales staff to securely access the organization's central file-storage repository.
  • Installation of antivirus management software that will reduce the amount of time the security staff spends managing its antimalware systems.

Both of these are worthy initiatives and it's easy to make a security or business case for either in isolation. However, the team only has time to implement one. How is Joe to choose?

After asking a few questions, he determines that the firewall installation will save quite a bit of time for the sales staff as well as the central office staff. He estimates that these individuals are currently spending about 20 hours a week emailing files back and forth, which will be completely eliminated if the sales staff has access to the central storage system. On the other hand, the security team spends about 10 hours per week managing antivirus software, and the new package will reduce this to 5 hours per week.

Assuming that everyone in the organization is paid the same rate (this is too simple for the real world; you'll want to plug in actual salaries if you have them), it's clear from this cost/benefit analysis that the firewall installation is the project that will save the most money in the long run. If you consider the security benefits of both projects to be equal, the firewall project should be implemented first and the antivirus management project should come later.

Hopefully, this tip has given you a few ideas that will help you think about security within the context of your business. Remember, as with any support function, information security should always exist to serve the needs of the business, rather than the other way around!

About the author:
Mike Chapple, CISA, CISSP, is an IT security professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles, including the CISSP Prep Guide and Information Security Illuminated.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Information Security Management,   Business Management: Security Support and Executive Communications,   Network Intrusion Prevention (IPS),   Network Intrusion Detection and Analysis,   Enterprise Network Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network Security Tactics
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Network access control technology: Over-hyped or underused?
Screencast: Smoothwall offers firewall defense in lean times
Screencast: Samurai offers pen-testing nirvana

Business Management: Security Support and Executive Communications
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
New partnerships, creative thinking help security bust recession
How to align an information security framework to your business model
Service-focused security offers best value to organization
Cybersecurity Act of 2009: Power grab, or necessary step?

Network Intrusion Prevention (IPS)
Best Intrusion Prevention and Detection Products
Port scan attack prevention best practices
Lesson 4: How to use wireless IPS
Lesson 1 quiz: Risky business
Hacker attack techniques and tactics: Understanding hacking strategies
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
I'll be watching you: Wireless IPS
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
Network Intrusion Prevention (IPS) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
security  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts