Skip the navigation
Opinion

Data security in a converged network (Part 1)

By Joel A. Pogar, Siemens Information and Communication Networks Inc.
July 17, 2003 12:00 PM ET

Computerworld - Technology that allows voice over IP (VOIP) has been available for a number of years, but it has only recently been widely accepted in business. There has been a strong and growing value proposition for the replacement of traditional private branch exchange (PBX) systems with VOIP. The technology has matured considerably, and the benefits of return on investment, communications flexibility and the concept of "one network" are powerful drivers for companies to deploy VOIP today.

One of the most significant issues around the deployment of VOIP systems has been security. In the wake of Sept. 11, 2001, security is no longer an optional line item when ordering any high-tech system. There has been a lot of discussion around VOIP security, and there seem to be more questions than answers.


In this three-part series, some of the most common security questions and answers about VOIP will be presented. This article is intended to be vendor-neutral; therefore, specific products won't be discussed, but I will explain the major security concepts and issues when deploying a VOIP system.


What's the difference between a threat, a vulnerability and a risk?


While this question isn't specific to convergence, it's important to understand the differences among them.


  • A threat is an external security issue represented by a natural or man-made attack. For example, a lightning bolt is a natural attack, since the lightning can threaten the safety and security of a data network. Likewise, an external intruder is a man-made threat that attempts to compromise a network.

  • A vulnerability is a specific degree of weakness of an individual computer or network exposed to the influence of a threat. For example, if you haven't applied the latest security patch to the operating system of your Web server, then you have a vulnerability because that computer system is exposed to potential intruders.

  • A risk is the degree of probability that a disaster will occur in light of the existing conditions, and the degree of vulnerability or weakness present in the system. The key difference between a threat and a risk is that a threat is related to the potential occurrence of a security issue, whereas a risk is the probability of an incident occurring based on the degree of exposure to a threat. Risk, for security purposes, is usually calculated in dollars and cents.
It's important to realize that you may have a vulnerability, but without a threat, you have no risk. Evaluating each one of these factors is critical to knowing what security exposures you have, how critical they are and what effect they will have in your environment.

Does VOIP introduce any new security vulnerabilities to an enterprise network?


VOIP, by itself, represents a new "vector" for potential security issues but does not introduce any vulnerabilities that haven't been seen before. Some experts have argued that digitizing voice and placing it on a data network makes voice communications more accessible and easier to intercept. I would have to agree with this point. In a traditional, analog environment, physical access to a switch or wiring closet is usually necessary to intercept communications between two parties. By placing voice traffic on a data network, one could intercept a voice communication by capturing the associated packets as they traverse a large network. Attackers have already developed easy-to-use tools that are widely available.


There are other concerns about VOIP from a risk management perspective, such as keeping all your eggs in one basket. For example, if your data network was to experience a critical failure, you would be without voice and data communications. The impact to your business could be greater if there was a prolonged outage of both systems. Therefore, you need to ensure that your organization has adequate business continuity and disaster recovery plans.





Advice


Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs