Skip the navigation

Security Manager's Journal: Making the most of time between trips

Mergers have our manager on the road a lot. But meanwhile, his other security projects can't languish.

By Mathias Thurman
September 29, 2008 12:00 PM ET

Computerworld - My company has undertaken so many mergers and acquisitions lately that I'm in danger of doing M&A amelioration full time. My practice is to visit all of the acquired companies' operations. At each site, I ask lots of questions, review architecture diagrams and firewalls, and conduct assessments of the infrastructure.

Trouble Ticket

Issue: Multiple mergers and acquisitions mean plenty of travel to Europe and Asia for site visits.

Action plan: Fit in other projects during those brief times not spent on the road.

Many of these sites are overseas, so I spend a lot of time flying to Europe and Asia. And when I get home, I have to spend hours creating assessment reports and remediation plans.

But I can't let my other initiatives shrivel from neglect. I have to make sure I keep all of them on track in between my trips. Here's what I've been up to lately.

First is the never-ending policy project. I've written all the new policies now, so I'm just trying to get my CIO to ratify them. Then I'll be able to upload them to the company intranet and get the word out about them. The policy ratification process has been slow, but I think I've figured out how to move it along.

Instead of overwhelming the CIO with 25 new policies, I've scheduled a series of monthly one-hour meetings. At each session, I present him with three to five policies, with summaries on a separate sheet that highlight the main tenets of each policy and any changes from what we currently have in place. He glances at the full policies, we discuss each one, and I usually end up making some minor changes.

After I am finished, the policies are ready for his signature. Besides sparing the CIO a grueling marathon session to go over all the policies at once, this approach fits in better with my current M&A schedule.

Also well under way is the secure FTP project. We're replacing an archaic FTP server that runs WU-FTP on an old version of Solaris with Tumbleweed Secure Transport for transferring information among employees, vendors, customers and partners. Besides increased security, we're gaining things like the ability to resume file transfer after a connection has been lost and notification features for uploads and downloads. Because technicians will be immediately notified when a customer uploads a maintenance file from one of our products, we will have a competitive advantage. In addition, the Web-based interface can be customized with our logo, giving it a professional look. I'll also be able to streamline FTP site provisioning by creating a Web-based form for that process that not only will have proper management authorization, but will also bill the proper cost center in order to manage the license fees.

I've received the report for the vulnerability assessment of our VMware deployment. Fortunately, no critical issues were found, but some fairly serious shortcomings will need to be remediated. We are going to have to harden the VMware ESX Server and VirtualCenter. The ESX Server is a Linux server responsible for managing server, memory, storage and networking resources as they relate to multiple virtual machines. VirtualCenter, which we'll be using to centrally manage our virtual machines, runs on a Windows server. If it were compromised, someone would have control of more than 250 critical servers at their fingertips.

I've scheduled a meeting with the virtualization team. I'll invite the consultant who performed the assessment as well, so the expert will be on hand to defend his findings should the deployment team push back on the remediation tasks.

I've got about a week before I hit the road again. In the meantime, I hope to make some headway on these tasks and continue to attend to my many other infosec duties.

This week's journal is written by a real security manager, "Mathias Thurman," whose name and employer have been disguised for obvious reasons. Contact him at mathias_thurman@yahoo.com.

Join in. To join in the discussions about security, go to computerworld.com/blogs/security.

Read more about Security in Computerworld's Security Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs