Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Four steps for protecting your internal networks

Mudge, Intrusic Inc.   Today’s Top Stories   or  Other Security Stories  
 

Sign up to receive Security Resource Alerts

September 9, 2004 (Computerworld) -- In the sciences, there are general principles that can apply to all environments. The principles of physics (i.e. the general laws) are ubiquitous across disciplines. Why should the information security field be any different? It turns out that it isn't.
In my experience, the following general principles have proved beneficial. Companies can apply them with existing internal resources.
1. Map security around business functions
In few areas is the relationship of security to business functions more obvious than in comparing electrical utilities with industrial refineries. Both business models use a segmentation structure around Supervisory Control and Data Acquisition and/or distributed control systems. While both electrical utilities and refineries have these environments, the refineries, in general, have a much more secure implementation of this model. Was this due to particular security requirements? No. Upon querying technical experts from both industries, the rationale became clear: One field had to be much more competitive in the business realm than the other. Industrial refineries had to compete in the business market, while utilities were subsidized and regulated by the government.
If one company operated at even a fraction of a percentage more efficiently and cost-effectively than a competitor did, that business had an edge in the public markets. Tremendous amounts of effort were spent designing and making networks and systems perform core technical requirements in a way that was as efficient and organized as possible. These efforts resulted in networks with a relatively high security baseline. More important, they provided a solid foundation for future security components that might be desired in the future.
Without the economic driver of competition for the electrical utilities, the optimization and maximization of underlying business architectures didn't receive the same attention. As various utilities markets are deregulated, many players find themselves in the position of having to make a profit. However, the underlying infrastructure lacks a foundation solid enough to confidently run critical business tasks, let alone withstand hostile attacks.

2. Define information and data labeling and handling guidelines
Although an arduous initial task, implementing data classification, labeling and handling guidelines will pay huge dividends in the long run. Many companies will invest substantial capital toward vulnerability assessments, network intrusion-detection systems and security best-practice guidelines. Unfortunately, few of these companies ever embrace information labeling and classification guidelines.
If an engineer comes across a business memo he doesn't understand, what are the odds that this information will be handled in a secure fashion commensurate with the memo's value? Conversely, if a secretary receives an e-mail that carries with it an attachment of source code, will the secretary automatically know whether it's permissible to forward this e-mail to a recipient

Continued...
1 | 2 | 3 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Need help sorting through the hype of cloud computing? Here's some IDC research on the benefits, barriers -- and what..." Read more...
"Stephen Spoonamore offers more details on what I was trying to drive home in my recent column: Because individual votes..." Read more...
Read more Security posts or See all Blogs
Wall Street's collapse puts IT spending in (some) peril
Oracle tries to step up on high-end databases
Microsoft fights Ballmer testimony in 'Vista Capable' suit
More top stories...
IBM launches Bluehouse, a Facebook for business
iPhone grabs top smart phone spot
Apple doesn't need Jobs, analyst says
Here's the scoop on widespread fables about Bill Gates, the iPhone kill switch, Internet2, Al Gore and more.
Add these Wi-Fi devices to your network for a new world of wireless productivity and entertainment.
Users who abandoned Firefox and Internet Explorer for Google's Chrome browser are starting to revert to their old favorites.
One of the pleasures of Linux is that you can try out different distros to see which one works best for you. Here are five to take for a spin.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
The Enterprise Search Zone
Software as a Service Zone

Ads by TechWords

See your link here
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Intercept Spam & Viruses
Download this whitepaper to learn how to outsmart spam & viruses, compliments of MessageLabs.
(Source: MessageLabs) Register for a complimentary 30 day trial of MessageLabs' new managed Anti-virus and Anti-spam security solutions. MessageLabs guarantees complete protection against all known and unknown email threats. By providing 24 hour support, your business can increase productivity and decrease risk.Register now for a complimentary trial and receive a free datasheet.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Case Study: Golder Associates
Case Studies Real Customers, Real Results
Psomas Achieves Global Work-Sharing and Accelerates the Mobile Worker
View more whitepapers