Skip the navigation

Security Manager's Journal: Another delay is another black eye for security

Projects are supposed to get security reviews at every phase of the project cycle. When that doesn't happen, you get delays.

By J.F. Rice
February 16, 2009 12:00 PM ET

Computerworld -

This week, I ran into unexpected trouble. A project is ready to go live, but it never received a security review. And it has a lot of the elements that would go into a worst-case scenario: a third party, sensitive data, the Internet and no plans for encryption.

We've done a good job of getting security reviews into all phases of our project cycle, including the concept stage. That means we've been able to avoid most last-minute security roadblocks. So, how did this one fall through the cracks?

Maybe because it's a third-party application that's accessed over the Internet via software on end-user systems. People tend to think of that sort of implementation as a hands-off situation. Of course, most people don't think like a security manager.

When I look at what's planned with this implementation, I see data -- in fact, employee payroll information -- being sent to a third party. I see a looming nightmare, since the company that hosts the financial application in question seems to have no understanding of, or ability to provide, encryption.

Trouble Ticket

At Issue: A project is about to go live, and it has never been reviewed by security.

Action Plan: Jump in, take a look, and demand that the data involved gets encrypted.

As soon as I heard about this (secondhand), I asked for a meeting with the project manager. I couldn't believe what I was hearing. Employee names, Social Security numbers and pay amounts were going to be transmitted over the Internet, with no encryption.

I told the project manager that we'd need a minimum of file-level encryption, preferably at the point where the data is created (in this case, in PeopleSoft). And I added that it should not be decrypted until it is used, ideally within the third-party application itself. I'm willing to compromise on exactly where the data is encrypted within our perimeter, but once it gets out to the Internet, it needs to be protected, in an unreadable form.

I wasn't saying anything new. Last year, we forced file encryption on many projects that involved third parties handling our sensitive information. In fact, this same project manager was involved in one of those earlier projects, so he knows all about this. I'm disappointed that so little of my message got through the first time, but at least I don't have to spend a lot of time educating him this time around.

It's too late for this project, though. The contract has already been signed, and the implementation is ready to go live. After I got involved, we had a couple of discussions with the vendor, which seems to have no idea how to use encryption software.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs