Comments
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..

2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
In many cases, the end of the year gives you time to step back and take stock of the last 12 months. This is when many of us take a hard look at what worked and what did not, complete performance reviews, and formulate plans for the coming year. For me, it is all of those things plus a time when I u...
SYS-CON.TV
Four Reasons Why Data Security Strategies Fail
It's important to maintain a high-level view

There are many reasons why a data security strategy could self-destruct, not the least of which is a new breed of highly motivated data thieves who stand to make a considerable profit on customer and other sensitive information in data centers. We're often so mired with putting out data security and compliance fires that we don't have time to step back and look at the high-level issues that could have prevented many of those fires from igniting in the first place. Let's review four of the critical reasons why the security strategies of many companies are unintentionally opening them up to increased risk.

  1. The Déjà vu Strategy: Doing more of what they have already done. I see this all the time. Companies beef up existing security hoping that it will address new security threats. I call it "outside-in versus inside-out security" because often the company will add more perimeter security rather than covering additional critical bases like core databases and edge data leaks.
  2. The Rules Are the Rules Strategy: Relying on policies, like access control, without properly monitoring what is actually happening in the environment. This is especially ineffective against the insider threat. Improved password management, authentication, and better access termination policies are all noble causes, but until a company can actually see what is going on with data, who is really accessing it, and what they are doing with it, they will leave data open to risk.
  3. The One Bite at a Time Strategy: Thinking about security in pieces rather than viewing it as a whole. For example, I have a laptop problem, an email problem or a database problem rather than a data security problem. One prime example is adding edge security like DLP (data loss prevention) and ignoring core security like DAM (database activity monitoring).
  4. The What's Hot Security Strategy: Approaching security from a perceived-value perspective, based on what seems to be the must-have technology at the moment, rather than a risk-management model. Many companies do not evaluate technologies by the risk they mitigate versus the cost to do so. Encryption is a good example. Some kinds of encryption can cost a great deal yet eliminate only a small amount of risk. There are other technologies that eliminate a great amount of data risk with a relatively small investment.

Data security is a complicated problem, but security strategies often fail for simple reasons. Stepping back and seeing the problem as a whole is difficult for administrators and managers on the front lines because their jobs require them to be in a reactive mode much of the time. It's up to the people who chart strategic direction to maintain a high-level view and avoid shortsightedness when creating security strategies. Losing perspective based on maintaining an outdated direction, lacking an ongoing security program assessment, ignoring the big picture when it comes to data risk, or leaning toward solutions with the most marketing dollars could mean that when it comes to increased data risk for your company, it will be déjà vu all over again.

About Prat Moghe
Prat Moghe is founder and CTO of Maynard, MA-based Tizor Systems where he drives market strategy, product vision, and technology thought leadership. An expert in compliance, security, networking and systems management, he is vice-chair of the PCI Security Vendor Alliance and authors the first data auditing blog at http://blog.tizor.com.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

SOA World Latest Stories
Yahoo’s critical negotiations with Alibaba to sell part of its stake in Alibaba back to the Chinese company have collapsed according to All Things Digital, a report later confirmed by CNBC. Apparently the collapse includes Yahoo’s parallel and intertwined negotiations with Softbank t...
Can you bring services from the cloud to your customers faster and have them adopt it with ease of use or bring the power of bundled services to the fingertips of your clients without creating new rigid ‘apps stove pipes'? Do you want to prevent your business running away to public and...
The Internet highway may start looking like a proverbial New York traffic jam at rush hour soon. Feel free to substitute any town you like because Cisco says there’s going to be a faster-than-expected 18x surge in worldwide mobile data traffic between 2011 and 2016. That’s when mob...
OCZ Technology Group, a provider of high-performance solid-state drives (SSDs) for computing devices and systems, on Tuesday announced the Z-Drive R4 CloudServ PCI Express (PCIe) flash storage solution, designed to accelerate cloud computing applications and reduce operating expenses i...
Many organizations have embraced, or are considering, the benefits of cloud computing – speed, flexibility, increased expertise, shared workload, reduced costs, etc. The benefits are many – but so are the risks. What are the threats to cloud security? Which parties assume responsibilit...
SoftLayer Technologies on Tuesday announced the immediate worldwide availability of SoftLayer Object Storage, a redundant and highly scalable cloud storage service that allows users to easily store, search and retrieve data across the Internet, with optional CDN connectivity, or across...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE