Data security in a converged network (Part 1)
Computerworld -
Technology that allows voice over IP (VOIP) has been available for a number of years, but it has only recently been widely accepted in business. There has been a strong and growing value proposition for the replacement of traditional private branch exchange (PBX) systems with VOIP. The technology has matured considerably, and the benefits of return on investment, communications flexibility and the concept of "one network" are powerful drivers for companies to deploy VOIP today.
One of the most significant issues around the deployment of VOIP systems has been security. In the wake of Sept. 11, 2001, security is no longer an optional line item when ordering any high-tech system. There has been a lot of discussion around VOIP security, and there seem to be more questions than answers.
In this three-part series, some of the most common security questions and answers about VOIP will be presented. This article is intended to be vendor-neutral; therefore, specific products won't be discussed, but I will explain the major security concepts and issues when deploying a VOIP system.
What's the difference between a threat, a vulnerability and a risk?
While this question isn't specific to convergence, it's important to understand the differences among them.
- A threat is an external security issue represented by a natural or man-made attack. For example, a lightning bolt is a natural attack, since the lightning can threaten the safety and security of a data network. Likewise, an external intruder is a man-made threat that attempts to compromise a network.
- A vulnerability is a specific degree of weakness of an individual computer or network exposed to the influence of a threat. For example, if you haven't applied the latest security patch to the operating system of your Web server, then you have a vulnerability because that computer system is exposed to potential intruders.
- A risk is the degree of probability that a disaster will occur in light of the existing conditions, and the degree of vulnerability or weakness present in the system. The key difference between a threat and a risk is that a threat is related to the potential occurrence of a security issue, whereas a risk is the probability of an incident occurring based on the degree of exposure to a threat. Risk, for security purposes, is usually calculated in dollars and cents.
Does VOIP introduce any new security vulnerabilities to an enterprise network?
VOIP, by itself, represents a new "vector" for potential security issues but does not introduce any vulnerabilities that haven't been seen before. Some experts have argued that digitizing voice and placing it on a data network makes voice communications more accessible and easier to intercept. I would have to agree with this point. In a traditional, analog environment, physical access to a switch or wiring closet is usually necessary to intercept communications between two parties. By placing voice traffic on a data network, one could intercept a voice communication by capturing the associated packets as they traverse a large network. Attackers have already developed easy-to-use tools that are widely available.
There are other concerns about VOIP from a risk management perspective, such as keeping all your eggs in one basket. For example, if your data network was to experience a critical failure, you would be without voice and data communications. The impact to your business could be greater if there was a prolonged outage of both systems. Therefore, you need to ensure that your organization has adequate business continuity and disaster recovery plans.
SecurityAdditional Resources![]() Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white.
Enter for a chance to WIN a PhaserTM 8860 network color printer!
![]() Microsoft
Save time and mitigate security risk. Deploy it now.
![]() Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.
Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase. White Papers & WebcastsShare our Strength Lower the Cost and Complexity of a Mobile Workforce through Automation Top 10 Things to Know about Data Protection Managing Mobility: Improve Data Security, Compliance and Manageability Managing Secure File Transfer to Save Time, Money and IT Resources Ponemon Study: The Business Risk of a Lost Laptop Security Convergence Equals Network Security Cost Savings Airport Insecurity: The Case of Lost Laptops Disaster Recovery 2008: Reduced Costs and Improved Performance Computerworld ReportsWhite PapersSponsored Links |



