ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

SME Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Letting go of your security worries

Matt Hines CNET News.com

Published: 26 May 2005 13:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Chris Hoff isn't ready to throw caution to the wind, but the CIO is defying the conventional mindset about outsourcing enterprise security.

To keep operations safe at Western Corporate Federal Credit Union — known to some as the "credit union to credit unions" — Hoff has a long list of security issues to consider. And for one important element of WesCorp's defence — testing its IT systems for potential weak points — he signed on with an outside software provider, Qualys.

Hoff said he had to change a few minds in WesCorp conference rooms to get acceptance for his decision to use hosted vulnerability management. Wescorp has been using Qualys' online applications for the last year.

"I don't think that it would be fair or prudent to say, 'The time is right; the applications are here. So you can just outsource all your security operations.' But there are places where [hosted applications] can work as well anything else," he said.

"When we looked at the various delivery models and compared costs at having to maintain and manage everything, including upgrades, the functionality and ease of deployment with hosted made for a very strong case," Hoff said.

The task of keeping up with security patches is one of the most demanding and frustrating jobs assigned to IT departments, which are often caught in a race to fix problems before an attack hits. For a network with more than 500 staff to serve, it can take more than 100 hours of work to do everything needed to fix just one flaw, according to Research and Markets.

With that in mind, companies that promise to take over the job of defending corporate networks against intrusions and vulnerabilities are likely to see their prospects take off, analysts say — especially as regulatory compliance becomes more of a concern.

The flow of threats such as the Sober virus is another ongoing worry. To help, Oracle puts out a monthly bundle of security updates, as does Microsoft, which pioneered the approach. But the various patch programmes can be a headache for administrators, as the tussle over automatic installation of Microsoft's Windows XP Service Pack 2 illustrated.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
278 out of 496 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Salesforce.Com - Expertise Required

Huxley Associates' Client based in the Berkshire area is currently recruiting for a contract Salesforce.Com Consultant. You will be advising my ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Application Support Analyst - SalesForce.com - Media - London - 40k

The purpose of the role is to provide technical and functional support for the IT systems used by the companys marketing and sales teams - ...

Vista Upgrade Blog

Microsoft's pre-modern message puts a...

Over at ZDNet.com, Ed Bott reports a first sighting of Microsoft's eagerly awaited $300 million ad campaign. Already the cause of much speculation, the consensus is that this will be... More

7 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment

Discussions

David Long David Long

Defragging: Merits?

Thursday 24 July 2008, 10:30 AM

12 posts