Part 3: Security response at a large company
Computerworld -
A large company with a large IT department and a dedicated security staff is in a unique position in relation to security response. It will have more resources, including more staff and more money and can accomplish more in terms of security, but it will also have more eggs to watch, and they will be in many different baskets.
In the previous articles in this series, we looked at the differing security responses in small or home offices (see story) and at midsize companies (see story). In the third and final part of this series, we'll examine the challenge of security response in the large business environment.
As in the case of a small company, a companywide security policy is crucial to the security process. A separate incident response policy is also needed to further specify all the actions that should be taken after a security incident. The policy should define all the company's protections from various risks, including internal abuse and lawsuits. This policy also should satisfy the due diligence requirements imposed by government regulations.
![]() | |
| Anton Chuvakin, Ph.D., GCIA, is a senior security analyst at a major information security company. His areas of expertise include intrusion detection, Unix security, forensics and honeypots. In his spare time, he maintains his security portal www.info-secure.org. |
Big and complicated
One important characteristic of large company security is its size. Having complicated perimeter defenses and thousands of internal machines on various platforms certainly doesn't add simplicity to security management. Huge amounts of security information are generated by firewalls, intrusion detection software and various access points (such as dial-up servers and VPNs) and systems on the LAN. It would be impossible to respond to all of this data.
In addition, few of the events mean anything without the proper context. For example, a single packet arriving at Port 80 of the internal machine might be from an employee within the LAN mistyping a Web address, which isn't important. Or it could be a port scan attempt within the internal network (critically important) or misconfigured hardware trying to do network discovery (of low importance).
Using automated tools to sort through all the incoming data should help to detect hidden relations between various security data streams. A simple example would be the slow "horizontal" port scan: Port 80 on IP 1.2.3.4, then Port 80 on 1.2.3.5, etc., as opposed to a "sequential" port scan with Port 80 on 1.2.3.4, then Port 81 on 1.2.3.4, etc.
A single packet arriving at the port will most likely go
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

