I have to admit that I am happy we now see the end of 2008! It has been an awful year...and a very good year...or as my friends (that used to be in the financial market) would say...the volatility has increased. The awful things is of course almost all related to the financial market but I would also claim that the bad weather during my vacation is as bad. Another summer like that and my wife will demand that we sell our sailing boat...and instead spend our vacations on a beach somewhere. This will lead to me being bored, kids who thinks that nature looks like the Canary Islands (that would probably be O.K for my teenage daughter...I still hope that I can save my other two kids) and even more time spend on airplanes. I cannot stand flying so when I fly I always take a drink, the more I fly the more drinks. I will probably end up drinking too much which will affect my job and this blog...so my carrier will go down the drain. All of this because of one lousy rainy summer!
One more thing before I will leave you alone for Christmas, there is a problem with Christmas gifts that seldom is discussed. After the kids have received all their new toys they turn to me to make them work. Suddenly I am transformed from my more theoretical approach in life to become an engineer, computer expert or assembler. So my Christmas evening will be spend reading manuals and I usually wreck some of the new toys. This year I have a plan; I will try to persuade my kids to get help from their Mother so I can inspect the work when it is done. I hope my plan will work…I will let you know.
Monday, 22 December 2008
Wednesday, 17 December 2008
Virtualisation and security
Virtualisation is not only hard to spell but seems to be the cure for all things that is wrong with any IT-infrastructure. The arguments for virtualisation ranges from everything from saving money to save the planet. As always, security is an issue that is rarely discussed to the surprise of no one.
Now I have to admit the underlying security problem is not really a virtualisation issue, it just becomes clearer when all servers become virtualised. There is a difference of having a hundred different servers in a network or one server that runs a 100 virtualised servers. The first thing that needs to be done is to put an application layer firewall between all users and the applications and then (which is as important as the firewall..) only give granular access to the users. An ordinary firewall will not work as they lack the granularity that is needed. Users should never have access to more information then what they need. With this approach the server is protected from attacks and “browsing” on the server is prohibited..and all access is logged. I also think that it is vital that all communication between the users and the server is encrypted…as I do not trust any network…inside or outside and that the device is checked BEFORE any access is given.
Now I have to admit the underlying security problem is not really a virtualisation issue, it just becomes clearer when all servers become virtualised. There is a difference of having a hundred different servers in a network or one server that runs a 100 virtualised servers. The first thing that needs to be done is to put an application layer firewall between all users and the applications and then (which is as important as the firewall..) only give granular access to the users. An ordinary firewall will not work as they lack the granularity that is needed. Users should never have access to more information then what they need. With this approach the server is protected from attacks and “browsing” on the server is prohibited..and all access is logged. I also think that it is vital that all communication between the users and the server is encrypted…as I do not trust any network…inside or outside and that the device is checked BEFORE any access is given.
Monday, 15 December 2008
Six days to the end of the world
I have spent time at some interesting conferences this autumn. One of them was in Brussels and was attended from the police, military and other security specialists. It is always interesting to learn from people that are users of the technology that we in the industry provide. Sometimes the problems are very, very different from the ones I encounter in my daily life, such as the discussion I overheard about the best way to dispose 10 000 kilos of drugs that came out of a big bust. It was discussed as a pure logistical problem.
You can say one thing about people in the security space; we are not the most optimistic people in the world. Put a bunch of us in a room and we will provide scenarios that will make the most optimistic person run for cover. In one of the seminars I attended we discussed what would happen if the supply of water, power and food where to be stopped. The conclusion was that it would take six days before the society would break down. I do not know if that is true but it gives a perspective on how vulnerable our modern life is for attacks.
We also discussed how long it would take to bring a company to its knees, the conclusion was that a service company would not last more then two weeks without Internet access.
Then we discussed which companies and organisations that where under the biggest threat for a political attack (terrorism with other words..). We did not really reach a conclusion because when we discussed it everybody seemed to be threatened. Here is a shortened list:
• Anyone in the financial sector
• Meat producers
• International companies with strong brands
• Power and other utilities companies
• IT-Security companies
• Media companies
• Oil companies
• Car industry
• Drug companies
• Defence industry
You can say one thing about people in the security space; we are not the most optimistic people in the world. Put a bunch of us in a room and we will provide scenarios that will make the most optimistic person run for cover. In one of the seminars I attended we discussed what would happen if the supply of water, power and food where to be stopped. The conclusion was that it would take six days before the society would break down. I do not know if that is true but it gives a perspective on how vulnerable our modern life is for attacks.
We also discussed how long it would take to bring a company to its knees, the conclusion was that a service company would not last more then two weeks without Internet access.
Then we discussed which companies and organisations that where under the biggest threat for a political attack (terrorism with other words..). We did not really reach a conclusion because when we discussed it everybody seemed to be threatened. Here is a shortened list:
• Anyone in the financial sector
• Meat producers
• International companies with strong brands
• Power and other utilities companies
• IT-Security companies
• Media companies
• Oil companies
• Car industry
• Drug companies
• Defence industry
Friday, 12 December 2008
How many point products does it take to build a secure environment?
The cost for IT-Security is a common topic when I discuss security with business managers. The general feeling seems to be that every year they spend more and more on security without seeing any real improvements. The threat level never seems to change. The obvious positives such as remote access and mobility are often forgotten.
I claim that new functionality does not always have to lead to increased costs. We just need to get out of the habit of using “point-products” for everything we do. My definition of such a products is a solution that solves one particular issue but does not cooperate with any other parts of the environment. A typical example is push emails to mobile phones. As I said many time, buy a VPN product that handles all types of access including mobility. It is then possible to treat all access equal. This saves money and increases security.
Point-products is also very hard to get rid off (they have always worked….you know… and we need to think about the guy in Farawayland that uses it on Thursday’s every second week).
The cost for running disparate products with little integration is often higher then expected. There is a need for more personal, upgrades takes longer time; training and support costs are higher etc etc.
The industry is starting to pick up on this, they supply more products and talk about one-stop-shop….and we customers end up with one supplier…and still have products that cannot be integrated.
Save some money and increase the security, get rid of point products.
I claim that new functionality does not always have to lead to increased costs. We just need to get out of the habit of using “point-products” for everything we do. My definition of such a products is a solution that solves one particular issue but does not cooperate with any other parts of the environment. A typical example is push emails to mobile phones. As I said many time, buy a VPN product that handles all types of access including mobility. It is then possible to treat all access equal. This saves money and increases security.
Point-products is also very hard to get rid off (they have always worked….you know… and we need to think about the guy in Farawayland that uses it on Thursday’s every second week).
The cost for running disparate products with little integration is often higher then expected. There is a need for more personal, upgrades takes longer time; training and support costs are higher etc etc.
The industry is starting to pick up on this, they supply more products and talk about one-stop-shop….and we customers end up with one supplier…and still have products that cannot be integrated.
Save some money and increase the security, get rid of point products.
Thursday, 11 December 2008
Who can you trust part 2
A while back I was invited to participate in a panel at a security conference. One of the things we discussed was how to treat the fact that human beings are security risks. I have been in many discussions like that before but this one was different. Usually the consensus is that users have to be trained in security so they do not do any mistakes. This in a way puts the blame on the users if anything goes wrong. Now the conclusion was different. Even if the users fail the security systems has to work. I think that this is a break-through in the IT world. In other parts of our life we already see this trend, cars is a good example. Cars gets safer and safer, roads get safer and safer and we have regulations so people at least know how to behave. People makes mistakes and sometimes they even commit crimes, we in the industry need to prevent mistakes to cause security breaches and to prevent crime. We need to have less technology focus and accept that people are people and make life easier for them.
Wednesday, 10 December 2008
Mobile Security..we always do the same mistake
I have spent a good deal of today talking to a frustrated system admin providing arguments of why it is not a good idea to open holes in firewalls because the CEO wants to read e-mails on his mobile phone. (Another good example how hard it can be for the business side and the IT side of a company to communicate.)
Sometimes I wonder why we do the same mistake over and over again. We buy point products to solve point problems. We then end up with an infrastructure which cannot be managed and is costly to run.
My argument is always the same when it comes to mobility: treat it as any other access form, use a proper VPN with 2-factor authentication, NAC and granular access control.
Sometimes I wonder why we do the same mistake over and over again. We buy point products to solve point problems. We then end up with an infrastructure which cannot be managed and is costly to run.
My argument is always the same when it comes to mobility: treat it as any other access form, use a proper VPN with 2-factor authentication, NAC and granular access control.
Tuesday, 9 December 2008
This is a good week
I have been recognised as an Most Valued Performer 2008 by Network Products Guide. What can I say...I am proud today as well. Another winner was the CEO of Google.
Subscribe to:
Posts (Atom)
