March 10, 2004 (Computerworld) --
PALM DESERT, Calif. -- In IT security, emotional reactions, panic and legislation are counterproductive. But intelligent risk management can enable organizations to face an uncertain future optimistically. That was the message from Merrill Lynch & Co.'s security chief to attendees at Computerworld's Premier 100 IT Leaders Conference here yesterday. David Bauer, first vice president and chief information security and privacy officer at Merrill Lynch, gave his audience a historical perspective on the evolution of IT security, starting with the Morris worm attack of 1988. That attack took the Internet by surprise, he said. There were no tools to fight back and no source of reliable information. Responses were uncoordinated, and the result was "complete havoc," Bauer said. He contrasted that with the Mydoom attack last month, when Merrill Lynch combined good tools with a coordinated and carefully planned response to understand and contain the threat after just one infection. That attack, he said, was "just another event." "The difference between then and now is tremendous," Bauer said, "and preparation is the key." Preparation requires a focus on risk management, intelligence-driven prevention and response, security at the data-object level and a focus on both the corporation and the individual consumer of technology. "It's easy to get somebody's password, so make the damage that can be done by an individual as small as possible," he said. Bauer also suggested that, since IT security is fundamentally a technology problem, it should be handled within the IT operation. Merrill Lynch's IT security strategy is built around strong organization; threat management, including intelligence, planning and instant response; comprehensive security services; attention to public policy, including active attempts to educate legislators; and agile response to the changing risk environment, he said. A key component of that strategy is dynamic risk assessment. Using tools such as scanners, log analysis, risk metrics and asset inventory, Merrill Lynch's security group produces a biweekly security brief analyzing and prioritizing current threats. "That allows us to go from a circle-the-wagons approach to intelligent risk management," Bauer said. In response to audience questions, Bauer said that as a percentage of the IT budget, Merrill Lynch's security service costs less than that of any competitors. "It's not about how much you spend but how well you spend it," he said. "We're not making vendors rich, but if we buy something, we use it." He also noted that about half of his spending is advisory, helping the company build secure systems, while the rest goes toward risk management, prevention and response. Bauer addressed the problem of legislation, which he said drives up costs and takes resources away from actual risk mitigation. "Part of our strategy is our Legislative Watch," he said. "We try to keep ahead of legislators and influence them, if not to cancel legislation at least to word it properly." He urged all corporations to do the same. Looking ahead, Bauer predicts that the threat picture will be "interesting." But with defenses built around thoughtful planning, he said, "I'm optimistic about our chances for success." Complete preconference survey results (registration required)
Moving to Windows Vista: The Promise, The Reality View this exclusive webcast today! Go to the webcast
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs. (Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more. Download this executive briefing
Record Capacity for Microsoft® Exchange 2007 With VMware and IBM System x3850 M2
Download this white paper today! (Source: VMware) The more that e-mail becomes an entrenched IT infrastructure application, the more that messaging administrators face numerous--sometimes conflicting--demands in the categories of availability, flexibility and cost. Employing a virtual solution can help avoid expensive over-provisioning of server computing resources, while improving management and disaster recovery. And ultimately, it can more than double the number of supportable Exchange 2007 users, as compared to a non-virtualized environment. This whitepaper explains how to break down the scalability barrier and respond faster to your mail system needs. Download this white paper
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
With the mobility of employees and the ease with which external devices can be brought in and out of a network, continuing to build your security plan for network servers and clients is a must. Fortunately, there is much that organizations can do to protect themselves from attacks - internal and external. Having the right policies, procedures and server configurations is critical...
Fired up about IT?Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day.
Companies today are realizing that competitive advantage is harder to sustain when based solely on gains in productivity and cost efficiency. The focus is shifting to invest more in business optimization initiatives which rely on trusted information to develop new insights that deliver better business results. But how can this be done efficiently in a business environment across multiple applications and processes. The answer is an Information Agenda - an innovative approach to transforming business information into a strategic asset for competitive advantage.
Webcast: The Automation of IT Compliance Programs: Reducing Risk, Cost and Complexity of Corporate Compliance
To meet the growing number of industry and federal regulations, businesses spend significant time, effort, and budget determining how to best meet continuously evolving IT compliance requirements this new Forrester Research and Juniper Networks Webcast led by industry experts who examine global IT security and compliance trends, common IT compliance issues and challenges, and best practices for successful IT compliance programs.
Whitepaper: Tackling the Top Five Network Access Control Challenges
The major challenge enterprises face today is how to create innovative business models and to increase productivity by opening the network to a dynamic workforce, while at the same time protecting critical assets from the vulnerabilities that openness and user mobility bring. In addition, to comply with industry and governmental regulations, enterprises must prove that they have stringent controls in place to restrict access to sensitive data. This paper describes the top five networking access control challenges that companies like yours are facing and solutions that they are deploying today.
Whitepaper: Addressing PCI Compliance with a Comprehensive Network Access Control Solution
The Payment Card Industry (PCI) is one of the most comprehensive data security standards in a cluster of regulations that have emerged over the past decade. Meeting its requirements is both complicated and expensive for many companies. Learn how a comprehensive access control solution allows retailers and consumer organizations adhere to the core tenets of PCI, and delivering the necessary information and reports needed for compliance audits. Download this white paper
Whitepaper: Control System Cyber Vulnerabilities and Mitigation of Risk for Utilities
Today's global industrial infrastructure includes thousands of electric utilities, water/wastewater management companies, oil and gas suppliers, chemical manufacturers and other facilities critical to daily functioning. Learn why relying on off-the-shelf operating systems and Internet-based remote access control to carry out production tasks, traditional control networks can leave today's global industrial infrastructures vulnerable to hackers, extortionists, worms, viruses and application-level attacks. Deploying network-based security can protect these at-risk systemswithout requiring infrastructure replacement. Download this white paper