Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


March 01, 2007

Security Pro VIP Update--March 1, 2007


RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

In this Issue:

  • Perspective: Experts on Security
  • February 2007 Articles in Print-Friendly Format
  • Coming this Month
  • Security Pro VIP Forum Now Available
  • Share Your Security Tips and Get $100

Perspective: Experts on Security

More-targeted attacks, customer authentication, businesses keeping a closer eye on employees and customer data, security company mergers and acquisitions, better integration of security with the rest of IT—these are a few of the trends that security experts are watching, according to a panel of industry analysts and another panel of security company executives assembled for the RSA Conference last month in San Francisco.

Andrew Jaquith of Yankee Group talked about the "professionalization of malware" and an actual "supply chain" that now exists from finding vulnerabilities through to delivering malware that exploits those vulnerabilities. "There's money to be made," he said, and "malware is a full-time job for people." Attacks are smaller, more targeted, more geared toward financial gain for the attackers. Art Coviello, president of RSA, the Security Division of EMC, gave the example of an attack levied from the Philippines against a credit union in Louisiana. He called this "puddle phishing" because of the small size of the target.

The panelists also said that attacks are increasingly using social engineering; for example, an attack might be designed for a particular company to look like a message coming from one or more employees inside that company. Jaquith noted that long term, security suites will be more behavioral and less reliant on signatures, but short term, companies have exposure in this area. Ray Wagner of Gartner agreed, saying, "There's a human factors issue here. Can we educate users enough? How do we signal them? You can have locks on the door, but users have to decide whether to open it or not."

Another human-related security issue for businesses is authenticating customers. George Tubin of TowerGroup mentioned that financial institutions are working to implement new authentication and fraud protection measures to comply with regulations that went into effect at the end of 2006. He noted that the Internet is very important for financial institutions because it promises a much cheaper and easier point of contact with customers—for example, for institutions to introduce new products and customers to manage their accounts. However, in the last year, financial institutions have had to communicate to users that they won't ask for personal info in email and they've quit putting links to their Web sites in messages. Clearly, the possibility of fraud has dealt a big blow to online banking and consumer confidence in it.

Companies are also focusing on their internal users and checking user computers before allowing them on corporate networks. Jaquith mentioned "the rise of the suspicious business" and surveillance of employees as being a trend. He also spoke of the blending of consumer and enterprise equipment (as in people taking their personal laptops to work) as being a challenge for companies. Both Richard Palmer of Cisco Systems and Ben Fathi of Microsoft on the executive panel mentioned access control and enforcing policies as being a hot area for businesses right now—not too surprising given Cisco's Network Access Control (NAC) and Microsoft's Network Access Protection (NAP) initiatives.

We all realize that data protection is another hot area, particularly with The TJX Companies data breach in the news right now. Jaquith likened the necessity of storing customers' personal information to asbestos or lead in its potential toxicity for businesses. I'm not sure there's an exact parallel here—customer data isn't a problem you can pay someone once to clean up—but I see his point, and it makes for a good quote.

The panel of security company executives, called "CEO Panel: A View from the Top," was actually a misnomer, as Coviello pointed out. A year ago, he was CEO of RSA and his fellow panelist, Tom Noonan, was CEO of Internet Security Systems (ISS). Now those companies are owned by EMC and IBM, respectively, and Noonan is general manager of IBM ISS. "There are no CEOs at this table," Coviello joked. He also said that EMC would be acquiring more security companies to broaden its portfolio and that security needed to be integrated into the IT infrastructure rather than being a standalone industry.

Others on the executive panel agreed that there would be more consolidation of security companies and that security integration was necessary and coming. Noonan also emphasized that companies are beginning to challenge the expense and complexity of security and consider security outsourcing and services as an alternative to trying to manage many disparate security products.

Renee Munshi, Security Pro VIP Editor

. . .


Already a VIP member?
Please log on to view the full article

Why become a VIP member?

VIP-only online access
VIP CD delivered twice a year: offline access to the entire Windows IT Pro article library
Monthly issue of your choice of Windows IT Pro or SQL Server Magazine

Subscribe Now
Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement