The future of security management: Why it's in network and systems companies
Computerworld - Network and systems management providers are best positioned to become the leading security management vendors.
Ten years ago, a period of time that even measured at Internet speed isn't all that historical, software companies that had been rapidly innovating technologies to help companies respond to the growing complexity of managing diverse systems and networks faced an interesting challenge: They discovered that innovation was no longer the key to success.
Technology companies that had accelerated through innovation found themselves shut out by the very companies they were trying to help. Instead, offerings with fewer of the latest gizmos and whistles that had been tightly coupled with complimentary services and applications found their way into the enterprise. The companies that succeeded were those capable of integrating network and systems management technology and deploying solutions across broad and diverse networks.
Ten years later, we are in a market state that economists define as an oligopoly: A handful of companies that manufacture and deliver comprehensive network and systems management suites. The good news is that the evolution from security products to integrated security systems has already begun. In about five or 10 years, the state of security management will mimic the present state of network and systems management, where only a handful of providers deliver products and services.
Why the history lesson? Because today's chief information security officers and other technology executives focused on enterprise security are seeking assurance that when they begin making hard security decisions they won't be forced to revisit those decisions. With hundreds of vendors and products, it's a confusing landscape, and answers are hard to find. Leaders must emerge in security management, and those leaders will have to demonstrate the following four characteristics:
- Understanding of security technology, both problems and solutions
- Understanding of enterprise integration and management
- Understanding of the changing face of risk inside the enterprise
- Sensitivity to the new responsibilities of the chief security officer
![]() |
|
| Ron Moritz, CISSP, is senior vice president and chief security strategist at Computer Associates International Inc. Earlier, he founded Moritz Technology Corp., a management advisory firm for security technology companies. He also was senior vice president and chief technology officer at Symantec Corp. and was CTO at Finjan Software, an Israeli security software company. He can be reached at ron.moritz@ca.com. |
But security is different than other technology, and it's not trivial. Arguably, it's more complex than network and systems management, and it's necessary to be immersed in the art of security in order to gain the domain knowledge upon which a broad management solution may be built. Most network and systems vendors don't have adequate expertise with respect to security. Even so, these vendors retain a key advantage over security pure plays: They understand the enterprise, they understand management, and they understand heterogeneous environments.
There are many common technology elements applicable to network, systems and security management: consoles, agents, correlation engines, repositories and analysis tools. There are also common functions for network, systems and security management that are applied for different purposes. In the case of systems management, event management and trouble-ticketing functions are oriented to problem resolution. In the case of security management, these functions are used to evaluate and mitigate threats in real time. In the systems management world, autodiscovery is used to build a topology map for root-cause analysis. In the security management world, autodiscovery is used for policy compliance -- that is, to discover and then analyze new systems for vulnerabilities. Configuration management is a key discipline for systems management, and the focus is software distribution. In security management, we are concerned about configurations for two reasons: security patch management and policy compliance. Historical reporting is used primarily for capacity management when applied to systems management and for audit compliance by those concerned with security.
Consequently, in the near term, security management will remain separate from network and systems management simply because it's complex. Because security management integrates key elements and collects data from various sources, including network devices, it can't and won't remain separate in the long term. Network and systems management vendors, which already control comprehensive management consoles and the network operations center, will leverage their relationship with the enterprise to incorporate security management.
- Souped-Up Security
- Farming Out Security: How to Choose a Service Provider
- Security and QoS Unite
- Security Begins at Home (With Telecommuters)
- The Almanac: Networking
Read more about Networking in Computerworld's Networking Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Make the Connection: Better Network Connectivity Drives Transformation
- Network connectivity is more than just plumbing. Leading organizations today see high-performance network connectivity as a critical enabler of competitive advantage, and not...
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Moving Service Management to SaaS
- Today, organizations can enjoy similarly substantial benefi ts by migrating their IT service management functions to a software-as-a-service model. This paper shows how...
- Achieving 360 Degree Network Visibility with Nimsoft
- 360° network visibility is critical for ensuring continuous availability of networks, servers, and applications-anything less could
have costly bottom-line implications.
All Networking White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- Try the OptiView® XG on your network - FREE
- The OptiView® XG is the first dedicated tablet with automated network and application analysis -- fastest way to root cause. XG raises the...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Networking Webcasts
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Virtualizing Government Infrastructure
- Achieving 360 Degree Network Visibility with Nimsoft
- Accelerating Cloud Performance with WAN Optimization
- The Changing Requirements of WAN Optimization
- Wainhouse Evaluation: 8x8's Virtual Office Pro VoIP and Unified Communications Solution
- Hospital Provides Secure Virtual Desktops to Clinical Staff
- Cloud Computing in the Public Sector
- Forrester Thought Leadership: Exploring the Potential Benefits of End-to-End Convergence of Data Center Networks
- Business and technology benefits of converged I/O Networking Infrastructures
- Make the Connection: Better Network Connectivity Drives Transformation
- Moving Service Management to SaaS
- Increase IT Performance from the Enterprise to the Cloud with WAN Optimization
- Accelerating Data Migration with WAN Optimization
- Resolve Top Network Conflicts
- Hay Group Moves Services to Secure Private Cloud
- Seven Corners Meets Travelers' Needs- Fast and Efficiently-with a Private Cloud Built on Cisco, NetApp, and Vmware
- UF version: Forrester Thought Leadership: Impact of FCoE & Unified Fabric on Enterprise Storage Environments
- Networking and Cloud: An Era of Change
- Coca Cola: Beverage Distributor Virtualizes Data
- Customized information views & Twitter events at New Fulcrum Point
- E-book: Discover Business-Ready Storage Systems For Oracle Environments
- Splunk translates machine data into "aha" moments for IT and the business.
- Converge your infrastructure with HP. Access a valuable case study in the CI Resource Center now.
- Panasonic Toughbook® mobile computers. Rugged. Reliable. Powerful.
- Protect your customers with VeriSign SSL, now from Symantec
- Citrix NetScaler. 2x faster 2048-bit SSL performance than F5. 50% lower SSL costs.
- Cisco's Unified Fabric delivers resiliency for optimal performance. Learn More
- The efficient small business server-from Colfax.
- Stop backing up. Start solving forward with CommVault® Simpana® software.
- Cognizant. Leading in Business, Application & Technology Services
- Cisco's Unified Fabric delivers resiliency for optimal performance. Learn More
- Still managing your projects with spreadsheets? Move your IT projects in the Cloud!
- M.S. in Information Studies at Northwestern University
- Tolly Performance Report "Citrix NetScaler with nCore Outperforms F5 BIG-IP"
- ITwhitepapers.com - Access thousands of white papers on 300+ technical topics.
- Leverage Your Cisco infrastructure for Superior Application Performance
- Learn about the AMD Virtual Experience
- "The Definitive Guide to Security Management" Chapter 1: Introduction to Security Management
- Introducing: Project Icebreaker
- Evolving Your Data Center for the Cloud
- Get Ethernet speeds from 1 Mbps to 10 Gbps - Comcast Business Class
- ExaGrid Gets High Marks in Independent Report from ESG
- Converge your infrastructure with HP. Access white papers, case studies, videos and more.
- Redefine Software support with HP
- Citrix NetScaler. 2x consolidation. For less than F5. Shift up to the Cloud.
- Ready for the Cloud? Not with F5. Shift to Citrix NetScaler. Shift up to the Cloud.
- Join the Conversation. Follow Oracle EPM & BI on Twitter Today.
- Arm Your Defense & Offense in 2012 with the Websense Threat Report
- MIT Sloan Executive Education. innovation@work
- A better way to share files, whenever, wherever. Accellion. Share Securely on the Go.
- Power your Dev Teams and Accelerate Software Delivery
- Connect with global CIOs now at Enterprise CIO Forum
- Pinpoint root cause of network issues up to 90% faster
- Download Microsoft's latest Data Protection Management tool
- Not All QSAs Are Created Equal: What You Should Know Before You Buy
- The arrival of Serial Attached SCSI (SAS) marks a new era in storage scalability
- The AMD Virtual Experience Virtual Trade Show
- "The Definitive Guide to Security Management" Chapter 1: Introduction to Security Management
