• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • London Evening Standard Business Connections Event, 'Use Technology to Boost Your Business'
    23rd May
    London, United Kingdom
  • 24th Annual FIRST Conference on Computer Security and Incident Response
    17th June - 22nd June
    Portomaso St. Julians, Malta
POPULAR PAPERS
  • Unifying electronic communications for enhanced security by Bloor Research
  • Data profiling: the business case by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "Mail your packages early so the post office can lose them in time for Christmas." - Johnny Carson

PAGE TOOLS
RECENT POSTS
  • Organisations struggle to safely and securely delegate sys-admin tasks
  • Quocirca's Report from Infosecurity Europe 2012
  • Who wants sweaty assets?
  • Organisations aren't performing device configuration backups with the diligence that they should
  • Windows desktop admin rights - an open door for malware?
  • Reducing the number of sys-admin errors
BLOG ARCHIVE
  • May, 2012
  • April, 2012
  • March, 2012
  • February, 2012
  • December, 2011
  • November, 2011
  • October, 2011
  • September, 2011
  • August, 2011
  • July, 2011
  • April, 2011
  • February, 2011
Blogs > Quocirca

Policy everywhere, with little to link it

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 11th July 2009
Copyright Quocirca © 2009
Logo for Quocirca

As Quocirca discusses in its freely available report "Content Security for the next decade", policies that define the way data must be handled are fundamental to good e-security practice, but where do you store the associated e-security policies? A written set of policies for handling data should be the starting point and such a document should be readily available to all employees and, where relevant, external data users for a given organisation. But policy can be enforced through a range of security tools in various parts of the IT infrastructure and this can lead to policy needing to be defined in several places.

For example, a policy may say that those in the financial department can share their spreadsheets with others in the same department but no one else. To enforce such a policy means that data in transit needs to be checked to see who is sending spreadsheets to whom, that on their PCs accountants must be prevented from copying spreadsheets to USB memory sticks and sending them to printers, and that such spreadsheets should only be stored in encrypted format—this requires one simple policy that can be enforced through technology, but probably only be defining it in three places.

Organisations can identify their users by getting them to authenticate against directories. User directories are generally accessed via a standard called LDAP (lightweight directory access protocol), and most security tools link to such directories to understand who users are and what groups they belong to. A well organised IT department may have just one user directory. But when it comes to policy, it usually needs to be defined time and again as there are no real standards and few generic repositories for policy that can be shared by multiple security tools.

IBM's initiatives this year around data security underline the problem. IBM can enforce encryption by defining policies in Tivoli Storage Manager, but to boost its offerings it has formed two new partnerships: Verdasys for the management of end points and Fidelis Security Systems for monitoring data in use. The problem is that both the new partners' products have policy engines too—so three in total; plenty of scope for duplication and inconsistency.

IBM is not alone. Other security vendors have addressed data security through multiple product lines developed in-house, acquired or via partnership. For example Symantec bought Sygate for end point security (now Symantec End Point Protection or SEP V11) and Vontu for data leak prevention or DLP (now Symantec DLP V9), both of which had their own policy engines.

CA, EMC/RSA, Trend Micro and Websense have all made acquisitions in the DLP and end point areas and face similar problems with co-ordinating policy. McAfee has one of the most centralised approaches. Its ePolicy Orchestrator (ePO) was developed in-house and is core to its security suite. All its acquired technology is integrated with ePO as well as with 50-plus partner products, all done using McAfee's own proprietary software development kit—so still not standards based. Meanwhile Microsoft has made some moves in this direction with the beta release of its new security management tools code named "Stirling".

Well defined and managed policy is essential to achieving and being seen to achieve good security practice. The industry needs a more co-ordinated approach on how policy is defined and shared across multiple products; it is possible for the management of people's identities through the use of directories and there are standards for access to these—what is needed now is to make it easier to find out what they are allowed to do.

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy

Published by: Electronicdawn Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761