Security 2.0: An Enlightened Era Of Enterprise Security

author-image
DQChannels Bureau
New Update

Just as Web 2.0 offers new ways to boost productivity, increase revenue and
costs, so will this next-generation of protocol. Security 2.0 expands protection
to the information and interactions themselves. This requires a more dynamic
view of security with technologies and processes that adapt to the reputation or
behavior of devices, people and applications

Advertisment

The more money and resources enterprises throw at security, the more the bad
guys seem to catch up. With every new technology innovation, comes a new and
sometimes worse threat to the business. It simply comes in a different form.

Loud and large-scale virus attacks launched for glory have been replaced with
stealth and financially motivated attacks seeking confidential information. Spam
is no longer just touting free Viagra. It's a delivery mechanism for phishing
attacks, identity theft and malicious code. And malicious code propagates not
just in e-mail, but through web plug-ins, IMs, smartphones USB drives.

The biggest threat to a company's brand and bottomline these days isn't from
hackers; it's from internal threats. It's the absent-minded contractor who
leaves their laptop on a plane with unencrypted sensitive information. It's the
disgruntled employee who steals thousands of customer credit-card numbers from
backend databases to sell on the black market.

Advertisment

Not just eliminating risks

Firstly, security shouldn't be about eliminating risk altogether. Without
risk, there is no opportunity. Instead, businesses and the IT and security
professionals should rely focus more on understanding the risks that will have
the biggest impact and then determine the best way to eliminate those risks.

There is no longer an impenetrable wall around organizations. People are the
new parameters. Employees are everywhere, partners are faceless, and your brand
isn't only in your hands. Companies are being forced to thrust their data to
third parties. In this environment, security can't only be about locking things
downs, It should help guide organizations, enabling them to thrive and have
confidence that their infras­tructure, information and interactions are
protected.

This is Security 2.0. Just as Web 2.0 offers new ways to boost productivity,
increase revenue and costs, so will this next-generation of security.

Advertisment

Security 2.0 is built on 1.0 but expands protection to the information and
interactions itself. This requires a more dynamic view of security with
technologies and processes that adapt to the reputation or behavior of devices,
people and applications. Security 2.0 is driven first by policy, then by
technology, and it will be operationalized to speed process and lower costs.

Protecting information, not just devices

The devices and systems we use are simply a suitcase for the real asset
we're trying to protect-the information. Since the perimeter can't be shut down,
security needs to focus on protecting the information itself. This requires
knowing where your information is, what is sensitive or confidential, who has
access to it, which needs access to it and how you make sure it's protected and
available when you need it. Answering these questions requires security,
operations and the business to work together.

A variety of new solutions are coming to light to prevent data loss-solutions
that enable companies to discover where information is in their organi­zation,
to set policies around entitlement or access, to filter confidential information
from e-mails and IM, or to monitor security incidents and database patterns that
could indicate malicious activities. But there's no silver bullet. Data loss
prevention can't be addressed with a single piece of technology, and there is no
substitute for understanding potential process weaknesses and training your
people.

Advertisment

No more one-size-fits-all security

Security should scale to the situation. The peanut butter approach to
security doesn't work in today's threat landscape and changing business
environment.

Take information controls for example. You wouldn't spend thousands of
dollars protecting pictures from the company picnic, but you would in order to
protect design documents, source code or credit card numbers. Your competitive
position and brand reputation depend on it.

In Security 2.0, security adapts to the level of risk, what needs to be
protected, and the reputation of entities trying to access your systems and
information. Security parameters should automatically change depen­ding on
whether a user is connecting to a network from inside the firewall or from an
airport kiosk. Decisions should be made based on the behavior of users,
historical information and the policies that are in place.

Advertisment

We see this happening already with anti-spam solutions, which analyze the
behavior and reputation of IP addresses to determine what messages get blocked.
Technologies like white listing and proactive threat protection in products like
Symantec Endpoint Protection are other examples of reputation-based security.

Operationalizing security

Probably the biggest shift in Security 2.0 is how it's driven within an
organization. Today most organizations are addressing security and risk in
silos, with groups implementing distinct and often disconnected processes and
technologies to mitigate the risks. These risks are often interconnected, but
unfortunately the processes and technologies are not.

In order to lower operational costs and make security more effective,
proactive and measurable, security needs to be embedded throughout business
processes from the very begining. Policies have to be consistently defined and
socialized before controls can be put in place. The most successful companies
look at policy first, and then implement the technology to automate it, not the
other way around.

Advertisment

By operationalizing secu­rity-standardizing, automating and driving down the
cost of day-to-day security activities, companies and IT can be much more
proactive when it comes to protection.

Security is an essential element to organizational health. We need to start
looking at security the way we look at our own health-focusing on preventative
care not simply seeing the doctor once you have a heart attack.

The author is MD, Symantec India