ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Toyota embraces open standards for security

Tom Espiner ZDNet.co.uk

Published: 24 Feb 2006 13:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Toyota gave its backing to open standards on Thursday, saying they were a key part of its security strategy.

Security products based on publicly available specifications will enable greater interoperability and help companies to measure how secure they are, Toyota believes.

"Open standards are the right approach," Richard Cross, information security officer for Toyota Europe, told ZDNet UK. "Standards bring benefits by lowering risks, and making results more standardised. We would see the benefits of going to different vendors that have the same solution," Cross added.

However, if a proprietary vendor had consistently excelled in an area, Toyota would consider using them. "We're not locked into any one way of doing things. Most of the time open standards are the right approach, though" said Cross.

Deperimeterisation — where the security emphasis is moved from the edge of the network and onto individual devices, and ultimately to individually encrypted data packets — had become a "fact" for Toyota with increasing employee mobility.

"Deperimeterisation has already happened. It's a fact of life, so deal with it," said Cross. "You need technical and procedural security, and overlapping defences, but the furthest extent of the network perimeter is the head of your employee — it's your people," Cross added.

Several major companies are backing deperimeterisation, including BP which said earlier this week that it had taken thousands of its laptops off its local area network. They now connect straight to the Internet even when used in the office.

"Hackers and virus writers have been a problem for years. But today there are very well-organised gangs in Russia, China and Brazil, with large teams and large server farms, that are determined to get their hands on our internal data and our users' identities," said Ken Douglas, technology director of BP.

"Typically, companies use a firewall and assume that the local area network is secure. But we've come to the conclusion that the LAN has to go," Douglas added.

Toyota rejected the need for compliance with external standards such as BS7799, a security code of practice.

"We're not aiming for [BS]7799 certification," said Cross, "and fewer than 5 percent of companies are attempting are attempting to gain it. We don't want our standards to be fixed — we want to be more agile. Heavily defined standards bring a lack of options, because you're tracking to external controls," Cross added.

"There's a danger of putting highly focused policies in place, as costs can outweigh benefits. If you have security turned up to such a level that you can't react because nothing is getting through, then that's not the right level of security," Cross added.

He also warned businesses to be cautious about purchasing products promising Sarbanes-Oxley compliance.

"The problem with Sarbanes-Oxley is that it means 20 different things to 10 different people. There's a tremendous wealth of folklore that has been built up around it in the IT sector. A lot of people are trying to push us into spending money on Sarbanes-Oxley compliance, but I trust our auditors," said Cross.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
102 out of 226 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Interim HR Consultant (Employee Relations)

I am currently resourcing on behalf of a large organisation based in Birmingham for a Interim HR consultant for a period of 3-6 months, specialising ...

Employee Relation\'s Specialist - 22,500

I require an experienced Employee Relations Officer to cover a 6 month maternity cover. You will be dealing on average upto 4 disciplinary and ...

IT Specialist

Perform user account setup and configuration - Allocate and track software licenses - Keep record of hardware assets (purchasing and re-allocation) - ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation