Security Manager's Journal: Can an enterprise run its security with Microsoft's tools?
The desktop group is pushing to abandon enterprise-class tools for built-in antivirus, firewall and encryption software from Microsoft. Is that any way to run a business?
Computerworld - Windows security tools may be good enough for home users, but can they meet the needs of the enterprise? Recently, my company's desktop team has been looking at Microsoft's built-in security software, with the idea that we should consider using those alternatives instead of commercial security software.
The desktop group is (finally) getting around to building a Windows 7 image for my company's desktop and laptop computers (yes, I know; it's about time). As part of this, the team is suggesting that we consider using Forefront, Windows Firewall and Bitlocker for antivirus, firewalling and encryption capabilities instead of the commercial products we now use with Windows XP. Why? Mainly because these tools are free and can be built into the image without as much work and testing as would be required with third-party software. The question is, are these tools as good as the commercial ones?
First, there's Forefront. This is antivirus software that is classically signature-based, like others. Is there really much differentiation among signature-based antivirus products? In my mind, the two key factors are effectiveness (how extensive is the malware signature database?), responsiveness (how quickly does the vendor turn around signature files for newly released, zero-day malware?) and manageability (how efficiently can administrators remotely install and manage clients and cleanup activities?). We currently have a top-tier antivirus product that works well and has had a good track record in my company's environment. That includes a typical less-than-24-hour response to zero-day malware, of which we do see a lot -- my company has an extensive presence in Asia, where much of the malware that gets onto our systems originates. I'm not particularly excited about giving up a perfectly good experience for an unknown quantity just because it's free.
My company's desktop security software suite includes active firewalling capability as well, which is able to whitelist applications based on administrator approval. This works very well, and I'm not at all convinced that Windows Firewall is going to give us a better experience. It seems like a perfectly good product for home users who want to manage their own applications, but that's a long way from what goes in on an IT shop of our size. We need administrators to configure and approve software communications, and as far as I know, Windows Firewall can't be centrally managed in a way that allows easy approval that can be quickly propagated throughout the organization. Yes, there's Group Policy, but is that really the ideal management tool?
Furthermore, I'm looking into a new software tool that performs behavioral profiling and adaptive blocking of application execution on end-user workstations. This commercial software runs on the computer for a while, building a database of behaviors that are then "locked in" as known-good. Any subsequent execution attempt must be approved before it is allowed. That seems to me to be much better than a classic network-port-control firewall.
More by J.F. Rice
- Security Manager's Journal: Upgrading, and looking for the best we can afford
- Security Manager's Journal: Rights can be so wrong
- Security Manager's Journal: Reining in network accounts
- Security Manager's Journal: Getting up to date on expired access rights
- Security Manager's Journal: Ready to hire, but coming up empty
- Security Manager's Journal: Can an enterprise run its security with Microsoft's tools?
- Security Manager's Journal: New ransomware attack hurts trustworthiness of Web
- Security Manager's Journal: A new look at vulnerability scanners
- Security Manager's Journal: Handling zero-days with zero staff
- Security Manager's Journal: Security training on the cheap
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
