May 15, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Data Integration/EII Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
Securing The Data Center: Bursting Your Security Balloon
09/10/2007
By Robert Grapes, Enterprise Solution Specialist, Cloakware
Untitled Document

Suppose we compare your data center to a water balloon. Both have a relatively secure perimeter. Both contain valuable content (water is the raison d'etre of a water balloon). Both face significant threats from pointed attacks. And in both cases, bad things happen when the perimeter is breached.

ADVERTISEMENT
Our Popular Webinars
Achieving Process Optimization and Efficiency in Manufacturing –
A BPM Best Practice
Accelerate Agility and Lower Costs by Virtualizing and Governing Your SOA
PepsiAmericas: Realizing Real-Time Communication
a refreshing approach to ESB and data integration
Avoid the SOA Pitfalls that Prevent ROI
BAM for BPM Survey Results Are In! Learn What’s Driving New BAM Investments
More Webinars

So why the comparison? Consider the following: How much do you spend to protect your data center applications from outside attacks? How about from attacks launched inside your network security perimeter? How secure is your valuable data against the misuse of privileged access accounts? When was the last time you changed all of your database passwords or all of your server passwords? Often, the answers to these questions reveal that a typical data center is about as secure as a water balloon.

In this article we burst the bubble of some common yet risky misperceptions about data center security. The goal is to get you thinking about threats that you may not have considered before. Then we describe some proven strategies you can adopt to resist these threats and improve the security of your valuable data.

Perimeter security is only a first step

If you're like many organizations, in the past decade you've focused your IT security efforts on strengthening the perimeter security of your data center. For instance, you may have installed an intrusion detection system (IDS). In our balloon analogy, this is like using thicker rubber: the barrier is stronger, but it remains the only defense against breaches.

A security strategy based on perimeter security assumes a lot of faith in the strength of the barrier. While it may be possible to resist known threats, the trouble is attackers eventually find new ways around barriers. And when they do, you'll want to have additional layers of defense in place to limit the scope and depth of the breach.

By itself, perimeter security is problematic for another reason: it's increasingly hard to define exactly where the perimeter is. As your company expands through organic growth or acquisitions, so too does the makeup and complexity of your network. Partners and customers gain ever more access to your online services, blurring the line between your network and theirs. New applications and technologies deployed beside your legacy systems create new administrative silos that may span historic network boundaries. How do you resolve the conflicting challenge of enabling easy access to and availability of your corporate data, while ensuring that the data is secure? It's tough to fill a balloon with water when the balloon itself is dissolving.

Page 1

More Top Stories
Is Big the New Small in Application Security? Gold Club Protected
Doing Risk Management Right Gold Club Protected
Defending Against the Cross-Site Scripting Attack Gold Club Protected
Penetration Testing Like a True Hacker Gold Club Protected
Managing IT Risk Effectively Gold Club Protected
Edging Towards Secure Application Development Gold Club Protected
More Top Stories
Related News
IBM and RIM Mobilize Web 2.0 Capabilities
NYSE Euronext Runs on Red Hat
Hewlett-Packard to Acquire EDS for $13.9 Billion
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
PepsiAmericas: Realizing Real-Time Communication
a refreshing approach to ESB and data integration

Date: May 28, 2008
Time: 13:00 PM ET
(17:00 GMT)

REGISTER TODAY!
Accelerate Agility and Lower Costs by Virtualizing and Governing Your SOA
Date: May 29, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  5 Reasons Mid-Market Companies Switch from Custom Code to Integration Appliances
The need for application integration is greater than ever within companies as they seek to link legacy applications with newer applications in order...Learn More
ebizQ also recommends
 BI for Telecom
 BI for Process Industries
 BI for Health Care
 BI for Decision Makers
 BI for Consumer Packaged Goods
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map