|
Most large organizations maintain a detailed corporate security policy document that spells out the "dos and don'ts" of information security. Once the policy is in place, the feeling is of having achieved 'nine-tenths of the law', that is, that the organization is in effect 'covered'. This is a dangerous misconception. Because much like in the world of law and order, while creation of law is fundamental, implementation and enforcement of law is what prevents chaos. Ignorance of policy does not exempt from punishment -- in this case in the form of security breaches Recent studies have shown that most employees, including IT staff, are often unaware of corporate security directives or even tend to ignore them. Ignorance of corporate policy or simple incapability to implement and enforce it can leave networks wide open to major security breaches. This is not only costly to fix, but can also ruin a company's reputation. Allowing the security policy become a 'white elephant' is just not an option. This is easier said than done. For security administrators, implementing the corporate policy on the ground is a complex and extremely time-consuming job. It starts with translating the guidelines into hundreds and even thousands of rules on a multitude of security devices. Dozens of configuration change requests come in every day, and administrators are required to manually check every single one to make sure they don't break the corporate policy. It's not surprising, therefore, that IT managers may ignore policy directives that make the difficult job of implementing change requests even more difficult. A conscious decision may not have been involved; the security managers may simply be unaware that a certain configuration change is against the policy and there is nobody around to sound the sirens. This results in major differences between the corporate policy and the actual security setup on the ground, and it's no simple task for security officers and auditors to bridge the gap. "We have more than 100 firewalls around the world," says Eli Beker, Security Officer at Comverse, a leading provider of software and systems for communications service providers. "Every day, several different teams of outsourced firewall administrators handle a list of dozens of change requests. Making sure our corporate security policy is followed can be like chasing a moving target." Why is corporate security policy enforcement so difficult? Eli is not alone. Corporate security officers today are coping with a growing list of challenges that make it harder and harder to get their jobs done. Here are a few examples:
Given the scope and complexity of network security operations today, it is clear that while most security administrators have the best of intentions, manual policy analysis and periodical audits is neither efficient nor effective. And it is also more expensive: administrators are spending more and more of their time on manual, repetitive tasks rather than on strategic objectives. Implementing even more than nine-tenths of the 'law', or in this case, a security policy, can only be achieved by automated solutions. By empowering continuous policy enforcement, they transform the audit process into what it should be: a routine report that demonstrates compliance with regulations. In addition to removing a significant security risk, automated solutions also result in a substantial savings of time and resources, since security teams often spend weeks preparing for and following up on external audits. A good solution is able to:
When choosing an automated solution, security officers should look for one that can centrally address distributed, global organizations with multiple devices, a variety of network security vendors and a geographically distributed workforce. With a robust Security Operations Management solution, Security Officers and Security Administrators can work together to proactively enforce corporate security policies effectively and efficiently - and with a lot fewer headaches. Tufin Technologies is exhibiting at Infosecurity Europe 2009, the No. 1 industry event in Europe held on 28th - 30th April in its new venue Earl's Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk |
