ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Analysts lament security 'arms race'

Marcus Browne ZDNet Australia

Published: 21 Nov 2007 17:22 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security is in a "trough of complacency" in the boardroom but getting it back on the agenda depends on security officers taking a different approach — evaluating the benefit of protecting against tomorrow's threats, not yesterday's, according to one analyst.

Security has dropped off the list of priorities for chief information officers due to an inability to calculate the effect it has on the bottom line, and a lack of foresight on the part of some security professionals, according to Gartner's research vice president and security specialist Jay Heiser, who addressed the Gartner Symposium in Sydney on Tuesday.

"I've had a lot of security officers tell me that there's no way they can do what they need to do to secure a network and come in under budget, but throwing money at it isn't going to solve the problem," Heiser said.

Matthew McGlashan, team co-ordinator at the Australian Computer Emergency Response Team (AusCERT), said that, while the value of security is difficult to calculate in dollar figure terms, security officers "need to be able to show a return on investment to the business".

McGlashan believes that one of the only effective ways of doing this is for security personnel to show what breaches have happened elsewhere as a means of illustrating security's continuing importance to the enterprise.

"There's almost no correlation between the effectiveness of security and the level of spending: in fact, the better the security the harder it is to account," said Gartner's Heiser, because there are no means to calculate what could have been lost from a potential breach.

Heiser claimed that enterprise security officers are often forced into a situation where they have to appear to be doing something about every possible risk at any given time, putting considerable strain on budgets and staff.

"Part of the problem is that IT managers can't identify a potential threat and then say to business managers that they're choosing not to mitigate against it," said James Turner, security analyst at IBRS.

Gartner's Heiser proposed a new security model — "Security 3.0" — based on determining acceptable risks and anticipating future threats rather than over-allocating resources to current dangers.

"We've got to change the orientation from after the fact to anticipating what the next move is going to be," Heiser said.

IBRS's Turner described the current environment as an "arms race", adding: "As soon as you implement one measure a new attack evolves; it would be really good if we could see into the future, and I suppose we need people to try and encourage us to do so."

Read this

Comment
Comment: Getting the knack of NAC

Network Access Control could be the best way to manage the security risks associated with the recent explosion in mobile devices connected to corporate networks

Read more +

Turner believes that the most important step in the evolution of risk management is the response of professionals to the new breed of attackers, as security officers are now squaring up against highly organised cybercriminals, and not just the "lone wolf hackers" of the past.

This has "definitely raised the stakes for security professionals", Turner said.

According to Gartner's Heiser, the most effective security regimes of the future will employ emergent technology as a means of reducing the threat posed by users in the security equation. Heiser said that leaving it up to users to secure their own systems was "essentially anarchy".

Heiser said that mandatory access control (MAC) is an example of a recent technology which still allows users access to sensitive data, but limits what they can do with it. In the case of a document, MAC can give administrators control over user operations such as copy and paste and printing, and disable them should they deem it necessary.

IBRS's Turner concluded: "The value in what Heiser is talking about is that it raises awareness about security. If it needs to be attached to a catchy term like Security 3.0 to get people's attention, then I don't see the problem with that."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
3 out of 3 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

IT Strategy Consultants Consulting

IT Strategy Consultants-00036731 Description IT Strategy Consultants Strategic IT Effectiveness (SITE) professionals focus on identifying and ...

Senior Consultant- Architecture and Business Analysis - London

The role involves: The primary focus of the role will be working on client projects, using a combination of management and technical skills to: - ...

CRM Technical Project Manager

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment