A growing number of technologies being widely adopted by businesses are challenging information security executives and their staffs, potentially endangering the security of government agencies, corporations and consumers worldwide over the next several years, according to a study.
New threats stemming from mobile devices, the cloud, social networking and insecure applications, as well as added responsibilities such as addressing the security concerns of customers, have led to "information security professionals being stretched thin, and like a series of small leaks in a dam, the current overworked workforce may be showing signs of strain."
The study also shows a severe gap in skills needed industry-wide. Information security professionals admitted they needed better training yet reported in significant numbers that many of these technologies are already being deployed without security in mind.
Other key findings:
-- As of 2010, Frost & Sullivan estimates that there are 2.28 million information security professionals worldwide. Demand for professionals is expected to increase to nearly 4.2 million by 2015, with a compound annual growth rate (CAGR) of 13.2 percent, creating career opportunities for those with the right skills.
-- Secure software development is a significant new area of focus for information security professionals worldwide.
-- Application vulnerabilities ranked as the No. 1 threat to organizations by 72 percent of respondents, while 20 percent said they are involved in secure software development.
-- Nearly 70 percent of respondents reported having policies and technology in place to meet the security challenges of mobile devices, yet mobile devices were still ranked second on the list of highest concerns by respondents.
-- Mobile security could be the single most dangerous threat to organizations for the foreseeable future.
-- Cloud computing illustrates a serious gap between technology implementation and the skills necessary to provide security. More than 50 percent of respondents reported having private clouds in place, while more than 70 percent reported the need for new skills to properly secure cloud-based technologies.
-- Professionals aren't ready for social media threats. Respondents reported inconsistent policies and protection for end-users visiting social media sites, and just less than 30 percent had no social media security policies whatsoever.
-- Viruses and worms, hackers and internal employees all fell in significance as top threats from 2008, the most recent year of the study.
-- The main drivers for the continued growth of the profession are regulatory compliance demands, greater potential for data loss via mobile devices and mobile workforce, and the potential loss of control as organizations shift data to cloud-based services.
-- Nearly two-thirds of respondents don't expect to see any increase in budget for information security personnel and training in 2011. Salaries showed healthy growth despite a global recession, with three out of five respondents reported receiving a salary increase in 2010.
Comment from Robert Ayoub, global program director - network security for Frost & Sullivan: In the modern organization, end-users are dictating IT priorities by bringing technology to the enterprise rather than the other way around. Pressure to secure too much and the resulting skills gap are creating risk for organizations worldwide. We can reduce the risks, however, if we invest now in attracting high-quality entrants to the field and make concurrent investments in professional development for emerging skills. As the study finds, these solutions are underway, but the question remains whether enough new professionals and training will come soon enough to keep global critical infrastructures in the private and public sectors protected. The good news from this study is that information security professionals finally have management support and are being relied upon and compensated for the security of the most mission-critical data and systems within an organization. The bad news is that they are being asked to do too much, with little time left to enhance their skills to meet the latest security threats and business demands.
Comment from W. Hord Tipton, executive director of (ISC)(2): We need a paradigm shift in our global cyber security strategy to address the skills gaps revealed by the study. (ISC)(2) believes it will take a combined effort of industry, government, academia and the profession to attract and educate a new generation of high-quality information security personnel and equip current professionals to address the latest threats.
About the study: The (ISC)(2)-sponsored study was based on a survey of more than 10,000 information security professionals worldwide conducted by Frost & Sullivan. The objective of the 2011 Global Information Security Workforce Study (GISWS) was to provide meaningful research about the information security profession to industry stakeholders, including professionals, corporations, government agencies, academia, and hiring managers.
Contact: The full study can be found here.
Showing posts with label Cyber security. Show all posts
Showing posts with label Cyber security. Show all posts
Friday, February 18, 2011
Thursday, December 2, 2010
Cloud Computing, Virtualization, Security, IT Cost-Cutting To Drive Modernization Of Messaging
With further cost reductions and a "tech refresh" projected for the broader IT market in the coming year, trends in cloud services, virtualization, data loss prevention and encryption security will continue driving greater adoption of modernized messaging infrastructures among Global 2000 enterprises in 2011, according to Sendmail.
While many organizations will continue moving to cloud-based IT infrastructures, demand for migrating certain components of the messaging infrastructure to the cloud will be tempered as a result of numerous security and compliance risks, causing many to opt for hybrid infrastructure solutions instead. Continued adoption of virtualization technologies and the increased demand for DLP and encryption security solutions will be key drivers influencing more enterprises to modernize their messaging infrastructures with Sentrion Message Processors. Additionally, there will be a decline of costly, stand-alone point solutions by Global 2000 companies in favor of a single message processing platform that can be customized to fit specific messaging needs in 2011 and beyond.
In 2011 the following enterprise messaging infrastructure trends will be realized:
-- Cloud Computing to Drive Greater Adoption of Hybrid Infrastructures: Despite increasing demand for overall IT cloud services, the cloud hype within the messaging infrastructure market will be tempered by many compliance and security risks that will prevent enterprises from migrating certain components of messaging infrastructure to the cloud. This will cause many large enterprises to require an intelligent e-mail backbone at the internal layer, and increase adoption of hybrid infrastructures that make use of both cloud services and in-house infrastructures.
-- Increased Demand for Virtualized Messaging Infrastructures: According to a recent Sendmail survey, a majority of companies in 2011 are expected to continue migrating components of their email infrastructure to virtualized environments to improve the efficiency and availability levels of their message delivery operations. As a result, enterprise demand for virtual messaging appliances, such as the Sentrion Virtual Message Processor(TM) (MPV), is expected to continue growing steadily in the coming year.
-- Steady Decline in Traditional Stand-alone Point Solutions: In order to reduce operating expenses and increase efficiencies, more Global 2000 enterprises will modernize messaging infrastructures on a single messaging infrastructure platform with customizable email architectures that allow messaging applications of their choice to be included as add-on options. This approach frees enterprises from having to implement costly and specialized stand-alone email products every few years, and will cause a steady market decline of those solutions moving forward. More specifically, there also will be continued erosion of traditional stand-alone point solutions in the email security space, due primarily to email filtering technologies becoming commoditized. As a result, companies will begin either moving those functions to the cloud or simply adding these applications onto their messaging infrastructures.
-- Stronger Demand for DLP and Encryption Solutions: With new privacy regulations in full effect throughout the U.S. and Europe, there will be even stronger demand for DLP solutions, however, those solutions are expected to focus on networks and storage, not the endpoint. Full DLP implementation is too difficult for most organizations to implement so many will develop a "good enough" solution to protect email and other network-based communications where most policy violations occur. As a result, this will lead to deeper integration with best-of-breed message processing and network DLP solutions. Driven by these same requirements and stronger corporate security policies, the need to provide confidentiality of sensitive information being exchanged is increasing, and driving demand for secure messaging solutions such as encryption. Automated application and policy-driven messaging, combined with a "good enough" DLP architecture will prove to be critical elements for organizations looking to reduce dependence on the end-user for determining what should be encrypted.
Comment from Don Massaro, Chief Executive Officer, Sendmail: There is a market shift occurring in the IT industry today. IT leaders are under enormous pressure to cut costs and fundamentally change the way they approach IT. Looking ahead to 2011, economic conditions are expected to improve and many enterprises with aging IT infrastructures are expected to begin investing in more efficient IT alternatives. As the paradigm shift occurs, and technology trends in cloud computing, virtualization and security continue to emerge, Sendmail is uniquely positioned to win big with Global 2000 companies looking to reduce operating expenses and increase efficiencies with modernized messaging infrastructures.
Contact: http://www.sendmail.com
While many organizations will continue moving to cloud-based IT infrastructures, demand for migrating certain components of the messaging infrastructure to the cloud will be tempered as a result of numerous security and compliance risks, causing many to opt for hybrid infrastructure solutions instead. Continued adoption of virtualization technologies and the increased demand for DLP and encryption security solutions will be key drivers influencing more enterprises to modernize their messaging infrastructures with Sentrion Message Processors. Additionally, there will be a decline of costly, stand-alone point solutions by Global 2000 companies in favor of a single message processing platform that can be customized to fit specific messaging needs in 2011 and beyond.
In 2011 the following enterprise messaging infrastructure trends will be realized:
-- Cloud Computing to Drive Greater Adoption of Hybrid Infrastructures: Despite increasing demand for overall IT cloud services, the cloud hype within the messaging infrastructure market will be tempered by many compliance and security risks that will prevent enterprises from migrating certain components of messaging infrastructure to the cloud. This will cause many large enterprises to require an intelligent e-mail backbone at the internal layer, and increase adoption of hybrid infrastructures that make use of both cloud services and in-house infrastructures.
-- Increased Demand for Virtualized Messaging Infrastructures: According to a recent Sendmail survey, a majority of companies in 2011 are expected to continue migrating components of their email infrastructure to virtualized environments to improve the efficiency and availability levels of their message delivery operations. As a result, enterprise demand for virtual messaging appliances, such as the Sentrion Virtual Message Processor(TM) (MPV), is expected to continue growing steadily in the coming year.
-- Steady Decline in Traditional Stand-alone Point Solutions: In order to reduce operating expenses and increase efficiencies, more Global 2000 enterprises will modernize messaging infrastructures on a single messaging infrastructure platform with customizable email architectures that allow messaging applications of their choice to be included as add-on options. This approach frees enterprises from having to implement costly and specialized stand-alone email products every few years, and will cause a steady market decline of those solutions moving forward. More specifically, there also will be continued erosion of traditional stand-alone point solutions in the email security space, due primarily to email filtering technologies becoming commoditized. As a result, companies will begin either moving those functions to the cloud or simply adding these applications onto their messaging infrastructures.
-- Stronger Demand for DLP and Encryption Solutions: With new privacy regulations in full effect throughout the U.S. and Europe, there will be even stronger demand for DLP solutions, however, those solutions are expected to focus on networks and storage, not the endpoint. Full DLP implementation is too difficult for most organizations to implement so many will develop a "good enough" solution to protect email and other network-based communications where most policy violations occur. As a result, this will lead to deeper integration with best-of-breed message processing and network DLP solutions. Driven by these same requirements and stronger corporate security policies, the need to provide confidentiality of sensitive information being exchanged is increasing, and driving demand for secure messaging solutions such as encryption. Automated application and policy-driven messaging, combined with a "good enough" DLP architecture will prove to be critical elements for organizations looking to reduce dependence on the end-user for determining what should be encrypted.
Comment from Don Massaro, Chief Executive Officer, Sendmail: There is a market shift occurring in the IT industry today. IT leaders are under enormous pressure to cut costs and fundamentally change the way they approach IT. Looking ahead to 2011, economic conditions are expected to improve and many enterprises with aging IT infrastructures are expected to begin investing in more efficient IT alternatives. As the paradigm shift occurs, and technology trends in cloud computing, virtualization and security continue to emerge, Sendmail is uniquely positioned to win big with Global 2000 companies looking to reduce operating expenses and increase efficiencies with modernized messaging infrastructures.
Contact: http://www.sendmail.com
Tuesday, November 9, 2010
Consumer Devices, Social Media and Video May Be Causing Company IT Policies To Bend Or Break
There is a disconnect between IT policies and workers, especially as employees strive to work in a more mobile fashion and use numerous devices, social media and new forms of communication such as video, a new survey has found. As technology trends alter the way businesses communicate and operate, more than two-thirds of workers surveyed believed their companies' IT policies could be improved, and at least two of every five (41 percent) said they break those policies to meet their needs.
Key findings:
1. Employee Awareness and Adherence to IT Policies
-- The study revealed that while most companies have IT policies (82 percent), about one in four employees (24 percent) are unaware that such policies exist. An additional 23 percent reported that their companies do not have IT policies on acceptable device usage. When combined, almost half of the workers in the study (47 percent) either do not have an IT policy on device usage or do not know that one exists.
-- For those employees who have an IT policy, 35 percent say IT does not provide an explanation or rationale for why it exists, which can result in apathy, misunderstanding and selective compliance.
-- Among workers aware of IT policy, about two of three (64 percent) feel it could use some improvement. These employees believe policies could be updated to reflect real-world needs and work styles, such as finding an acceptable medium between device usage, social media, mobility and work flexibility.
-- Of those employees who admit to breaking IT policies, about two of every five (41 percent) say it's because they need restricted programs and applications to get the job done -- they're simply trying to be more productive and efficient.
-- One of five (20 percent) employees worldwide said they break IT policy because they believe their company or IT team will not enforce it.
-- This research points to an issue among many businesses worldwide: the need to re-evaluate and update IT policies to align with the growing reality of a workforce that is demanding more enablement to be connected anywhere, anytime, with any device and any information in their work and personal lives.
2. IT Policy Toward Employee Use of Social Media, Devices
-- Social media use is restricted to varying degrees around the world and per company. Although half (51 percent) of the employees surveyed worldwide believe social media, while not work-related, contributes to work-life balance, two of five (41 percent) said they are restricted from using Facebook at their job, and one of three (35 percent) is restricted from using Twitter at work or with work devices.
-- More than one in four (28 percent) workers are restricted from using instant messaging at work or with work devices, and one in five (21 percent) are restricted from doing personal e-mail on work devices and during work hours.
-- Two of every three employees (64 percent) believe their IT teams and companies should loosen up and allow social media use during work hours with work devices, citing work-life balance as a key reason, particularly because many of them can work in a mobile, distributed fashion and put in longer hours as a result.
-- The use of personal devices like iPads and iPhones is also restricted to some degree. Globally, almost one in five (18 percent) employees are not allowed to use their iPods at work, and almost one in five (18 percent) are restricted from using personal devices like employee-owned laptops or phones.
-- The majority of employees (66 percent) believe they should be able to connect freely with any device -- personal or company-issued -- and access the applications and information that they need around the clock. Policy or no policy, many employees will simply do it, raising the question about how effective a policy is and how IT can update, enforce and ensure better compliance.
3. The Rise of Video in the Workplace
-- The use of video is on the rise as a form of consumer and enterprise communication. Globally, more than two-thirds of IT professionals (68 percent) feel that the importance of video communications to their company will increase in the future. This sentiment is particularly true among those in Mexico (85 percent), China (85 percent), Brazil (82 percent), and Spain (82 percent).
-- However, not all employees who wish to use video communications in the workplace are able to do so today. About two in five employees (41percent) said they cannot use video as a communications tool at work, with more than half of employees in the United States (53 percent), the United Kingdom (55 percent), Germany (55 percent) and France (60 percent) not having the capability of using video for workplace communications.
Comment from Marie Hattar, vice president, Borderless Networks, Cisco: The time spent between work and personal lives has blurred. Employees expect to access networks, applications and information anywhere, at any time, on any device. With the expansion of diverse devices in the workplace, along with the growth of video as a favored mode of communication, IT organizations are facing many policy and management demands on their networking infrastructure. The good news is that IT departments can allow employees to be productive and satisfy their desire to socially network on consumer or company-issued devices through the agility and flexibility provided by a Cisco Borderless Network Architecture.
Comment from Nasrin Rezai, senior director, Cisco Security: While most companies have IT policies, employees are not always aware of or knowledgeable about them. For those employees who are cognizant, policies are not always considered up-to-date or reflective of real-world business and lifestyle expectations, and as a result they are broken many times. The Cisco Connected World Report spotlights the disconnect between IT, employees and policies. As workforces become more distributed and the consumerization of IT becomes a fact of mainstream life, the importance of updating appropriate policies to accommodate employee needs while balancing risk and security becomes critical.
About the study: The study was commissioned by Cisco and conducted by InsightExpress, a third-party market research firm based in the United States. Cisco commissioned the study to maintain its understanding of present-day challenges that companies face as they strive to address employee and business needs amid increasing mobility capabilities, security risks, and technologies that can deliver applications and information more ubiquitously -- from virtualized data centers and cloud computing to traditional wired and wireless networks.
Contact: http://www.cisco.com
Key findings:
1. Employee Awareness and Adherence to IT Policies
-- The study revealed that while most companies have IT policies (82 percent), about one in four employees (24 percent) are unaware that such policies exist. An additional 23 percent reported that their companies do not have IT policies on acceptable device usage. When combined, almost half of the workers in the study (47 percent) either do not have an IT policy on device usage or do not know that one exists.
-- For those employees who have an IT policy, 35 percent say IT does not provide an explanation or rationale for why it exists, which can result in apathy, misunderstanding and selective compliance.
-- Among workers aware of IT policy, about two of three (64 percent) feel it could use some improvement. These employees believe policies could be updated to reflect real-world needs and work styles, such as finding an acceptable medium between device usage, social media, mobility and work flexibility.
-- Of those employees who admit to breaking IT policies, about two of every five (41 percent) say it's because they need restricted programs and applications to get the job done -- they're simply trying to be more productive and efficient.
-- One of five (20 percent) employees worldwide said they break IT policy because they believe their company or IT team will not enforce it.
-- This research points to an issue among many businesses worldwide: the need to re-evaluate and update IT policies to align with the growing reality of a workforce that is demanding more enablement to be connected anywhere, anytime, with any device and any information in their work and personal lives.
2. IT Policy Toward Employee Use of Social Media, Devices
-- Social media use is restricted to varying degrees around the world and per company. Although half (51 percent) of the employees surveyed worldwide believe social media, while not work-related, contributes to work-life balance, two of five (41 percent) said they are restricted from using Facebook at their job, and one of three (35 percent) is restricted from using Twitter at work or with work devices.
-- More than one in four (28 percent) workers are restricted from using instant messaging at work or with work devices, and one in five (21 percent) are restricted from doing personal e-mail on work devices and during work hours.
-- Two of every three employees (64 percent) believe their IT teams and companies should loosen up and allow social media use during work hours with work devices, citing work-life balance as a key reason, particularly because many of them can work in a mobile, distributed fashion and put in longer hours as a result.
-- The use of personal devices like iPads and iPhones is also restricted to some degree. Globally, almost one in five (18 percent) employees are not allowed to use their iPods at work, and almost one in five (18 percent) are restricted from using personal devices like employee-owned laptops or phones.
-- The majority of employees (66 percent) believe they should be able to connect freely with any device -- personal or company-issued -- and access the applications and information that they need around the clock. Policy or no policy, many employees will simply do it, raising the question about how effective a policy is and how IT can update, enforce and ensure better compliance.
3. The Rise of Video in the Workplace
-- The use of video is on the rise as a form of consumer and enterprise communication. Globally, more than two-thirds of IT professionals (68 percent) feel that the importance of video communications to their company will increase in the future. This sentiment is particularly true among those in Mexico (85 percent), China (85 percent), Brazil (82 percent), and Spain (82 percent).
-- However, not all employees who wish to use video communications in the workplace are able to do so today. About two in five employees (41percent) said they cannot use video as a communications tool at work, with more than half of employees in the United States (53 percent), the United Kingdom (55 percent), Germany (55 percent) and France (60 percent) not having the capability of using video for workplace communications.
Comment from Marie Hattar, vice president, Borderless Networks, Cisco: The time spent between work and personal lives has blurred. Employees expect to access networks, applications and information anywhere, at any time, on any device. With the expansion of diverse devices in the workplace, along with the growth of video as a favored mode of communication, IT organizations are facing many policy and management demands on their networking infrastructure. The good news is that IT departments can allow employees to be productive and satisfy their desire to socially network on consumer or company-issued devices through the agility and flexibility provided by a Cisco Borderless Network Architecture.
Comment from Nasrin Rezai, senior director, Cisco Security: While most companies have IT policies, employees are not always aware of or knowledgeable about them. For those employees who are cognizant, policies are not always considered up-to-date or reflective of real-world business and lifestyle expectations, and as a result they are broken many times. The Cisco Connected World Report spotlights the disconnect between IT, employees and policies. As workforces become more distributed and the consumerization of IT becomes a fact of mainstream life, the importance of updating appropriate policies to accommodate employee needs while balancing risk and security becomes critical.
About the study: The study was commissioned by Cisco and conducted by InsightExpress, a third-party market research firm based in the United States. Cisco commissioned the study to maintain its understanding of present-day challenges that companies face as they strive to address employee and business needs amid increasing mobility capabilities, security risks, and technologies that can deliver applications and information more ubiquitously -- from virtualized data centers and cloud computing to traditional wired and wireless networks.
Contact: http://www.cisco.com
Keywords:
Cisco,
Cloud,
Cyber security,
IT Policy,
Video
Thursday, November 4, 2010
Companies Are Not Prepared To Address Risks Created By Cloud Computing, Other New Technologies
Less than a third of global businesses have an IT risk management program capable of addressing the risks related to the use of new technologies like cloud computing, according to a survey.
In spite of the rapid emergence of new technology, just one in ten companies consider examining new and emerging IT trends a very important activity for the information security function to perform.
A significant increase in use of external service providers and business adoption of new technologies, such as cloud computing, social networking and Web 2.0, is recognized to increase risk for 60 percent of respondents. Yet, in spite of this, less than half intend to increase annual investment in information security.
Over half of respondents state that increased workforce mobility poses a considerable challenge to the effective delivery of information security initiatives, due to widespread use of mobile computing devices. For almost two-thirds employees' level of security awareness is recognized as a considerable challenge.
Half of respondents plan to spend more over the next year on data leakage and data loss prevention -- up 7 percent from last year. To address potential new risks, 39 percent are making policy adjustments, 29 percent are implementing encryption techniques and 28 percent are implementing stronger identity and access management controls. For the first time, continuous availability of critical IT resources was identified as one of the top five risks. 23 percent of respondents are using cloud computing services, a further 15 percent plan to use within the next 12 months. For 85 percent of respondents, external certification of cloud service providers would increase trust; 43 percent state that certification should be based upon an agreed standard and 22 percent require accreditation for the certifying body.
Comment from Paul van Kessel, Ernst & Young Global IT Risk and Assurance Leader: Technology advances provide an increasingly mobile workforce with seemingly endless ways to connect and interact with colleagues, customers and clients. These advances represent a massive opportunity for IT to deliver significant benefits to the organization but new technology also means new risk. It is vital that companies not only recognize this risk, but take action to avoid it. As the mobile workforce continues to grow, so does the level of risk. In addition to implementing new technology solutions and re-engineering information flows, companies must focus on informing the workforce about risks. The delivery of effective, and regular, security awareness training is a critical success factor as companies attempt to keep pace with the changing environment.
About the survey: Ernst & Young's 2010 Global Information Security Survey was conducted between June and August 2010. Nearly 1,600 organizations in 56 countries and across all major industries participated.
Contact: http://www.ey.com
In spite of the rapid emergence of new technology, just one in ten companies consider examining new and emerging IT trends a very important activity for the information security function to perform.
A significant increase in use of external service providers and business adoption of new technologies, such as cloud computing, social networking and Web 2.0, is recognized to increase risk for 60 percent of respondents. Yet, in spite of this, less than half intend to increase annual investment in information security.
Over half of respondents state that increased workforce mobility poses a considerable challenge to the effective delivery of information security initiatives, due to widespread use of mobile computing devices. For almost two-thirds employees' level of security awareness is recognized as a considerable challenge.
Half of respondents plan to spend more over the next year on data leakage and data loss prevention -- up 7 percent from last year. To address potential new risks, 39 percent are making policy adjustments, 29 percent are implementing encryption techniques and 28 percent are implementing stronger identity and access management controls. For the first time, continuous availability of critical IT resources was identified as one of the top five risks. 23 percent of respondents are using cloud computing services, a further 15 percent plan to use within the next 12 months. For 85 percent of respondents, external certification of cloud service providers would increase trust; 43 percent state that certification should be based upon an agreed standard and 22 percent require accreditation for the certifying body.
Comment from Paul van Kessel, Ernst & Young Global IT Risk and Assurance Leader: Technology advances provide an increasingly mobile workforce with seemingly endless ways to connect and interact with colleagues, customers and clients. These advances represent a massive opportunity for IT to deliver significant benefits to the organization but new technology also means new risk. It is vital that companies not only recognize this risk, but take action to avoid it. As the mobile workforce continues to grow, so does the level of risk. In addition to implementing new technology solutions and re-engineering information flows, companies must focus on informing the workforce about risks. The delivery of effective, and regular, security awareness training is a critical success factor as companies attempt to keep pace with the changing environment.
About the survey: Ernst & Young's 2010 Global Information Security Survey was conducted between June and August 2010. Nearly 1,600 organizations in 56 countries and across all major industries participated.
Contact: http://www.ey.com
Keywords:
Cloud computing,
Cyber security,
Ernst and Young,
Risk
Thursday, October 21, 2010
Major Concern For IT: Use, Access And Control Of Data In The Cloud
Cloud computing raises serious security concerns among respondents to an IBM survey about the use, access and control of data: 77 percent of respondents believe that adopting cloud computing makes protecting privacy more difficult; 50 percent are concerned about a data breach or loss; and 23 percent indicate that weakening of corporate network security is a concern. Businesses see the promise of the cloud model, but security remains an inhibitor to adoption.
While an information technology (IT) foundation pertains to all cloud computing, providers and users do not generally rely on one generic model for data security. Both cloud providers and users should consider a variety of factors, including the kind of work a client wants to do in the cloud and the mechanisms and controls used. For example, clients who have collaboration tools and email work in the cloud should think about access and policy controls, while clients focused on healthcare in the cloud should be concerned with data isolation and encryption.
These findings have spurred IBM to launch a set of initiatives based on a two-pronged approach to improving cloud security: plan and assess the security strategy for the cloud and obtain security services from the cloud.
Source: IBM's Institute for Business Value 2010 Global IT Risk Study.
Contact: http://www.ibm.com/services/riskstudy
Contact: http://www.ibm.com/security
While an information technology (IT) foundation pertains to all cloud computing, providers and users do not generally rely on one generic model for data security. Both cloud providers and users should consider a variety of factors, including the kind of work a client wants to do in the cloud and the mechanisms and controls used. For example, clients who have collaboration tools and email work in the cloud should think about access and policy controls, while clients focused on healthcare in the cloud should be concerned with data isolation and encryption.
These findings have spurred IBM to launch a set of initiatives based on a two-pronged approach to improving cloud security: plan and assess the security strategy for the cloud and obtain security services from the cloud.
Source: IBM's Institute for Business Value 2010 Global IT Risk Study.
Contact: http://www.ibm.com/services/riskstudy
Contact: http://www.ibm.com/security
Keywords:
Cloud computing,
Cyber security,
IBM
Thursday, October 7, 2010
Government, Companies Must Do More To Ensure Cyber Security
More than 71 percent of respondents to a recent online survey are concerned that their company is not equipped to protect itself from cyber attacks, while approximately 88 percent think the government is not equipped to protect itself.
Other findings:
-- The overwhelming majority of respondents (93 percent) believe cyber attacks are on the rise.
-- Respondents cited viruses and malware (67 percent) and DoS attacks (50 percent) as significant threats to organizations today.
-- Respondents (nearly 74 percent) expect their service provider to provide protection against cyber attacks.
-- The clear majority of respondents (90 percent) believe the best way to protect against cyber attacks is with a solution that detects, analyzes and mitigates unwanted, unwarranted or malicious traffic in real time.
Many fear critical networks face significant threats It is no surprise that the majority of survey respondents feel cyber attacks are increasing with alarming frequency. News reports of various worms, bots, viruses and identity theft have put the public on high alert. But despite an increased awareness of cyber attacks and a renewed effort by the Obama administration to fight cyber threats, few respondents feel critical government networks and company networks are adequately protected (12 percent and 19 percent, respectively).
Not only do respondents believe more cyber attacks are being levied on critical networks, an overwhelming majority (95 percent) believe those attacks are increasing in sophistication, as compared with attacks from a year or two ago. Survey results indicate an inability to protect sensitive and confidential data (69 percent) is a top concern among respondents. This is especially true in a cloud environment.
Responsibility of protection placed on carriers Although malicious activity on the Web has undoubtedly prompted most -- if not all -- organizations to put some sort of network security in place, more than 73 percent of respondents feel the onus of security should fall to their respective carriers or service providers. While not part of this study, we believe the reasons for this expectation are because of resource constraints in most organizations, the relative scarcity of skilled personnel, and the lack of widely available tools to detect and mitigate sophisticated attacks.
With a rise in the complexity and sophistication of attacks, the type of security tools that service providers deploy may well be a differentiator as customers begin to understand the real, devastating threats present in the cyber world.
As more networks become compromised, it is evident that standard approaches using signature- and policy-based software and hardware such as malware/anti-virus, firewalls, IDS/IPSs, and SEMs alone or in combination are critical but insufficient. Rather, a multi-tiered system based on vulnerability analysis and risk assessment of the data contained in the network -- enabling complete network and data visibility in distributed, heterogeneous networks and real-time processing and policy enforcement -- will emerge as a more desirable and complete solution.
Realizing that one company cannot possibly offer technology and services to cover the vast needs among organizations, cyber security vendors must cooperate with each and form a "cyber security ecosystem" and to offer more value to their customers. In an ecosystem, vendors interoperate with others in their ecosystem -- such as combining the best of forensics, visualization, data mining and storage -- in addition to their own cyber security solution. This integrated approach seems more valuable as it enables "best of breed" solutions to be combined based on the risk assessment and vulnerability analysis. By extending a vendor's product set through partnerships, cyber security vendors add critical value to their product and provide the best possible system for network protection and management.
Comment from Greg Oslan, CEO and president of Narus: Narus sponsored this survey to uncover what's important to the people most affected by malicious cyber activity -- the network and security professionals. Armed with these results, Narus can bolster its campaign to arm the world's most critical networks with cyber protection -- a solution that will provide the ability to see clearly and act swiftly.
The Narus survey focused on cyber security in the United States. Sponsored jointly with Converge! Network Digest and Government Security News, the survey queried a cross-section of security professionals in a variety of industries. The survey questions were developed by Narus, Converge! Network Digest and Government Security News, with input from noted telecom and security industry pundits. Opinions were gathered online from respondents, representing a cross-section of professionals in a variety of industries. One-on-one interviews were conducted to add more depth to the survey.
Contact: http://www.narus.com
Other findings:
-- The overwhelming majority of respondents (93 percent) believe cyber attacks are on the rise.
-- Respondents cited viruses and malware (67 percent) and DoS attacks (50 percent) as significant threats to organizations today.
-- Respondents (nearly 74 percent) expect their service provider to provide protection against cyber attacks.
-- The clear majority of respondents (90 percent) believe the best way to protect against cyber attacks is with a solution that detects, analyzes and mitigates unwanted, unwarranted or malicious traffic in real time.
Many fear critical networks face significant threats It is no surprise that the majority of survey respondents feel cyber attacks are increasing with alarming frequency. News reports of various worms, bots, viruses and identity theft have put the public on high alert. But despite an increased awareness of cyber attacks and a renewed effort by the Obama administration to fight cyber threats, few respondents feel critical government networks and company networks are adequately protected (12 percent and 19 percent, respectively).
Not only do respondents believe more cyber attacks are being levied on critical networks, an overwhelming majority (95 percent) believe those attacks are increasing in sophistication, as compared with attacks from a year or two ago. Survey results indicate an inability to protect sensitive and confidential data (69 percent) is a top concern among respondents. This is especially true in a cloud environment.
Responsibility of protection placed on carriers Although malicious activity on the Web has undoubtedly prompted most -- if not all -- organizations to put some sort of network security in place, more than 73 percent of respondents feel the onus of security should fall to their respective carriers or service providers. While not part of this study, we believe the reasons for this expectation are because of resource constraints in most organizations, the relative scarcity of skilled personnel, and the lack of widely available tools to detect and mitigate sophisticated attacks.
With a rise in the complexity and sophistication of attacks, the type of security tools that service providers deploy may well be a differentiator as customers begin to understand the real, devastating threats present in the cyber world.
As more networks become compromised, it is evident that standard approaches using signature- and policy-based software and hardware such as malware/anti-virus, firewalls, IDS/IPSs, and SEMs alone or in combination are critical but insufficient. Rather, a multi-tiered system based on vulnerability analysis and risk assessment of the data contained in the network -- enabling complete network and data visibility in distributed, heterogeneous networks and real-time processing and policy enforcement -- will emerge as a more desirable and complete solution.
Realizing that one company cannot possibly offer technology and services to cover the vast needs among organizations, cyber security vendors must cooperate with each and form a "cyber security ecosystem" and to offer more value to their customers. In an ecosystem, vendors interoperate with others in their ecosystem -- such as combining the best of forensics, visualization, data mining and storage -- in addition to their own cyber security solution. This integrated approach seems more valuable as it enables "best of breed" solutions to be combined based on the risk assessment and vulnerability analysis. By extending a vendor's product set through partnerships, cyber security vendors add critical value to their product and provide the best possible system for network protection and management.
Comment from Greg Oslan, CEO and president of Narus: Narus sponsored this survey to uncover what's important to the people most affected by malicious cyber activity -- the network and security professionals. Armed with these results, Narus can bolster its campaign to arm the world's most critical networks with cyber protection -- a solution that will provide the ability to see clearly and act swiftly.
The Narus survey focused on cyber security in the United States. Sponsored jointly with Converge! Network Digest and Government Security News, the survey queried a cross-section of security professionals in a variety of industries. The survey questions were developed by Narus, Converge! Network Digest and Government Security News, with input from noted telecom and security industry pundits. Opinions were gathered online from respondents, representing a cross-section of professionals in a variety of industries. One-on-one interviews were conducted to add more depth to the survey.
Contact: http://www.narus.com
Keywords:
Cyber security,
Narus,
Security
Subscribe to:
Posts (Atom)