Advertisement
Promo

Security threats Toolkit

Google gives glimpse into security strategy

Tim Ferguson silicon.com

Published: 11 Apr 2008 09:04 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has outlined some of the methods it employs to keep its IT security tight.

Google director of product management Scott Petry — founder of Postini, which is now owned by the search giant — gave the low-down on the web giant's approach to security at the RSA Conference in San Francisco this week.

Petry said: "Google is possibly the number-one target on the internet today. We get an enormous amount of activity against our systems."

He added: "We can't do everything and we know that. No security measure is 100 percent perfect."

Petry pointed out that the increasing number of different devices and mediums available — such as YouTube and the iPhone — is having a huge impact.

He said: "The base tenets of security aren't changing, but the world around us is. The data is finding different ways to get out into the world."

One way in which Google tries to reduce its exposure to risk is by using an army of external testers to "hammer" code, with the aim of revealing and reporting any vulnerabilities on new releases.

Petry explained: "If you don't know what your risk is, you don't know how to manage it."

Google also uses a neighbourhood-watch approach, asking people to confidentially report vulnerabilities they discover. Close competitors have taken part in this programme and Google returns the favour.

Security training is also very much part of the Google culture, Petry said. "Educating people about security is about the most important thing a security professional can do."

New recruits — known as "nooglers" — are thoroughly trained in the company's security policies, while a peer-review process means new code is checked a number of times before going live.

Petry also said that Google establishes "guard rails" for employees — for example, the use of technology that measures the strength of internal passwords when users first create them.

Credit: How Google keeps its tech security tip top from silicon.com

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

INIFiles: Getting those legacy files i...

Handling INI files can be a little tricky these days when you have to consider new security restrictions, virtualized environment restrictions (App-V and Citrix) and legacy applications... More

Post a comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters