Composite approach critical to effective security

December 2007 Information Security

Organisations struggle to find the resources to maintain a balance between security and operations.

But automated, integrated security management enables organisations to set up an immediate framework to monitor enterprise security and address all concerns in realtime, says Ulrich Weigel, EMEA director of security management practice at NetIQ (distributed and supported in South Africa by 10Net ICT Solutions).

Automated and integrated security management opens up a plethora of opportunities by integrating existing and new security systems and software with strategic security processes and practices. Constantly changing hardware requirements, software changes and regulatory compliance make integrated security mission-critical for many organisations. Only integration gives organisations full visibility into what is happening on their networks and allows them to act accordingly.

But integration must follow the correct methodology that offers a united front of people, processes and technology.

That amounts to involving employees from each business unit in the process to secure an action plan to implement agreed on security systems and procedures. Secondly, it requires internal coordination of structures, roles, responsibilities and reporting relationships. Lastly, businesses must certify programmes, which entail each business unit deciding, within certain bounds, the timescale in which its responsibilities can be introduced.

Security central nervous system

That results in thoroughly amalgamated realtime intrusion detection, log archiving, analysis capabilities, forensic capabilities and fault tolerance with other benefits and features attached to specific products, such as Web-based access consoles. Every server, router, switch, firewall and appropriate application reveals its activities to this process for monitoring, reaction and proactive measures. It offers businesses a security central nervous system that allows technicians, managers and executives to interpret, correct and enhance smooth and stable operations.

Although this approach sounds as if it is intended for large South African banks and insurance companies only, it is not. Regardless of the size of companies, they can derive the same basic benefits: clear visibility and the opportunity to take appropriate action. Those that need to comply with regulations only have a further need to employ this approach.

But how do they do it? The best way is to protect the investments they have already made. Integration is a common requirement today and best-of-breed tools exist to integrate most security solutions. It is imperative to ensure that all security solutions in organisations are integrated since it is critical to have all security information available.

Failure means reinventing the wheel

Failure to do so, besides the legal ramifications of failure to comply with regulations, means reinventing the wheel. That is costly and leaves companies reacting to security issues instead of proactively catering to them before they consume valuable IT dollars in fixes.

IT dollars are an increasingly rare commodity. Integrated security, if properly planned and rolled out, offers great return on investment (ROI). Loopholes are closed, communication barriers removed and processes employed for repeated actions. Ensuring that processes are transparent to all parties and that they understand them from their particular points of view allows them to employ the correct measures in reaching strategic business goals, again saving unwarranted expense.

Some pundits may suggest that good system administrators could take care of this problem without the need for automated systems, additional security solutions and the integration tools that may be necessary to link existing software into the loop. However, corporations sometimes work against themselves. Change processes and procedures prohibit rapid action. For example, missing patches cannot be installed because the ramifications to applications must first be investigated across the organisation. Without integrated security, that takes far longer than is necessary and often required, leaving corporate systems exposed.

Another strong argument in favour of integrated and automated security solutions is that the field becomes enormously complex. There are multiple operating systems to consider, applications abound, networks interconnect, files are spread across departments, divisions, businesses and geographies, databases are larger, more complex and geographically dispersed than ever before. Forget about maintaining a custody chain for audits. Even performing a simple log file correlation rapidly becomes tricky in such environments.

Information critical

Integrating them is so critical because administrators, who have a higher priority in organisations today, cannot afford to miss information. Without centralised log file administration, it is nigh impossible to manage them and removes the ability to conduct forensic analyses.

Information is the greatest threat to organisations today. Not having it, or having only partial information, has dire implications for organisational security and one of companies' most critical assets - data. Automated systems are the only method for effectively bridging the gap between the multiplicity of solutions employed in modern corporations and the administrative guards that watch over them.

Administrators need a comprehensive solution consisting of several components. However, each solution will contain different components depending on its intended objective. But all security solutions should factor in the three pillars of people, process and technology, incorporating existing components and fostering tightly coupled integration. The critical question to answer when selecting components is: how can we sufficiently report the state of security without drowning in different types of reports, multiple Excel spreadsheets and non-updatable PDF documents? The biggest challenge is obtaining a reporting utility that allows integration of all key aspects and becomes a 'role-based model' to give different people access only to appropriate information based on their role in the organisation.

Generally, solutions should contain the following components:

* Policy and process management.

* Systems management.

* Identity and access management.

* Incident and event management.

* Process automation management to enable macro process handling and integration of IT runbooks.

Integrated solutions with those components will be both reactive and proactive. They will provide continually updated audit reports for compliance against regulatory standards, best practices or other criteria to ensure ongoing changes are tracked. They will detect and prevent changes to operating systems and applications if required. They will alert in realtime and give predictive warnings.

That meets the minimum baseline that all systems require and convergence of systems and security management will ensure that all-important aspects of the IT lifecycle are covered.

For more information contact 10Net ICT Solutions, +27 (0)11 783 7335, [email protected], www.10net.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Upgrade your PCs to improve security
Information Security Infrastructure
Truly secure technology today must be designed to detect and address unusual activity as it happens, wherever it happens, right down to the BIOS and silicon levels.

Read more...
Open source code can also be open risk
Information Security Infrastructure
Software development has changed significantly over the years, and today, open-source code increasingly forms the foundation of modern applications, with surveys indicating that 60 – 90% of the average application's code base consists of open-source components.

Read more...
DeepSneak deception
Information Security News & Events
Kaspersky Global Research & Analysis researchers have discovered a new malicious campaign which is distributing a Trojan through a fake DeepSeek-R1 Large Language Model (LLM) app for PCs.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Survey highlights cost of cyberdamage to industrial companies
Kaspersky Information Security News & Events
The majority of industrial organisations estimate their financial losses caused by cyberattacks to be over $1 million, while almost one in four report losses exceeding $5 million, and for some, it surpasses $10 million.

Read more...
Digital economy needs an agile approach to cybersecurity
Information Security News & Events
South Africa is the most targeted country in Africa when it comes to infostealer and ransomware attacks. Being at the forefront of the continent’s digital transformation puts South Africa in the crosshairs for sophisticated cyberattacks

Read more...
SIEM rule threat coverage validation
Information Security News & Events
New AI-detection engineering assistant from Cymulate automates SIEM rule validation for SecOps and blue teams by streamlining threat detection engineering with automated testing, control integrations and enhanced detections.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.