Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Part 2: Security response in a midsize office

December 30, 2002 12:00 PM ET

Computerworld - How can you make security more effective under the constraints of a small or medium-size company?
In Part 2 of this series, we look at this environment and at the similarities and differences with the home-user case discussed in Part 1 (see story).
Small and medium-size businesses probably have no dedicated security staff. Their attitude toward security is to try to stay out of trouble. In this sense, small and midsize companies handle security the way people handle the security of their home office systems -- but with important differences that I'll outline below. These businesses often have employees who would astonish security professionals with questions such as, "Why would somebody want to hack us? We have nothing that would interest hackers." Today, most IT professionals understand that server disk storage, CPU cycles and high-speed network connections have a lot of value for malicious hackers and alleged cyberterrorists.
Even though they're small, these businesses are more regulated and have more administrative requirements than a private citizen in a home office. These requirements might include responsibilities to shareholders, fear of litigation for breach of contract, professional liability and many others. Thus, the level of security and accountability would need to be higher than in a home office. Most organizations connected to the Internet now have at least one firewall and some sort of DMZ setup for public servers (Web, e-mail, FTP, remote access). Many are deploying intrusion-detection systems (IDS) and virtual private networks (VPN). All these technologies raise new concerns about what to do with signals coming from them, since companies rarely hire new security staff just to handle those signals.

Anton Chuvakin
Security responses for such an organization would likely focus on high-severity threats. While it's well known that many low-severity threats, such as someone performing port scans, might be precursors to more serious attacks, such as an attempted break-in, a small company would rarely have the personnel to investigate those types of incidents.
Ideally, security reports should focus on attacks that are more serious and that actually have a chance of succeeding (unlike, say, exploits for services that are not installed). A central Syslog server (for the Unix environment) would be valuable; and using freeware tools such as Logcheck from Psionic Technologies Inc., Swatch and logsurfer could help in handling a flood of logging


Jump to comments

Security

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...