Security Isn't Just Avoiding Microsoft
Computerworld - We’ve all heard IT professionals imagine how secure their networks would be if they just didn’t have to use any Microsoft products.
I’ve had to listen to clients kvetch for hours on end about how Microsoft makes their lives miserable and how everything would be better in a Microsoft-free world. Tony Bove wrote a whole book with that theme, Just Say No to Microsoft, and plenty of blogs have taken up the cry.
It’s time for all the people who have entertained this fantasy to stop deluding themselves.
How would life without Microsoft be different? It wouldn’t be in any meaningful way for those in charge of network security; there would just be a different vendor peddling the dominant operating system.
Networks in a world in which Apple had won the operating systems wars would still be insecure. What’s that, you say? The Macintosh has had far fewer bugs reported and patched than Windows? That’s true, but it’s a consequence of the minuscule market penetration of Mac OS. If the Mac had enjoyed a market share of upwards of 80 percent for the past couple of decades, it would have been the focus of every hacker and script kiddie on the planet. And you might be lamenting the minuscule market share of that scrappy operating system vendor in Redmond, Wash.
If you put computers on a network and open that network to the outside world via the Internet, you’re going to have security problems, regardless of whether you’re running Windows, Mac OS, Linux or an operating system you created in your spare time. By all means, we need to run the safest operating system we can, fortify our networks and police the whole thing. But once we’ve done all that, we’re left with one unalterable fact: Users will still make errors galore. Training can help. But for a bit of perspective, consider commercial air transportation. The hardware is about as safe as possible, and pilots are trained as thoroughly as surgeons. But accidents happen, and they’re usually the result of pilot error.
User errors have long been the bane of security. In a sense, true security requires a paranoia honed to a fanatical edge, but sometimes even fanaticism isn’t enough. After all, no one has surpassed the Nazis when it comes to fanatical paranoia. Yet even the well-trained German soldiers of World War II broke a fundamental rule of cryptography and reused the same keys. That mistake might be the only reason this article wasn’t written in German.
So, what needs to be done? You must require users to attend formal information security training and awareness programs. No one should be left out. Set minimum security training and awareness requirements that all workers must meet -- even janitors and others who have no system access. Step up the requirements for those who have access to corporate information systems (most workers would fall into this category), and establish exhaustive requirements for employees in computer-related positions of trust, such as security staff and systems programmers.
Microsoft
Additional Resources



White Papers & Webcasts
Achieving Rapid AIX Data Recovery for Credit Union Core Processing Applications
Continuous member service is an important deliverable for credit unions, and the continued growth in assets and members means that the impact of...
Complying with PCI without Going Broke
Do a better job saving money and securing your data. Watch now.
Breakthrough Data Recovery for IBM AIX Environments
This white paper provides a road map to the most effective strategies and technologies to protect data in AIX environments and provide fast...
Get the Instruments You Need to Become an IT Security Hero
View an online demo that shows how you can quickly bullet-proof your internet security with the new iPrism 6.4 web filter, and you'll...
Continuous Data Protection (CDP) in IBM AIX and i5/OS Environments
A rewind button for applications, files and transactions? That's what continuous data protection (CDP) technology provides to managers of IBM AIX and i5/OS...
Sunny Skies Ahead- Evolving Your Security Infrastructure for the Cloud
Register for this webcast now!
Policy Automation by Design
Does your company have a policy strategy that covers all the bases? Read this white paper to learn about a strategy that can...
Secure and Compliant Collaboration and Access
Download Now

