home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Special Survivor's Guide Issue
F E A T U R E  
SECURITY

The Survivor's Guide to 2002

  December 17, 2001
  By Mike Fratto

Online Only: Rational Responses to Irrational Events

Printer Print Full Article
Printer Print This Page
E-Mail E-Mail This URL
It's been a tough year for Microsoft and its IIS. Several major vulnerabilities, a number of successful attacks against IIS servers, insurance companies charging a higher premium for IIS-based Web sites and Gartner recommending that "enterprises hit by both Code Red and Nimda immediately investigate alternatives to IIS" have all added to its misery. Yeah, go ahead, rip down all your IIS servers. Retool your Web applications from ASP to PHP or PERL. And do it now. That will surely be less painful than putting into place the proper patches, building a strong front end and doing a host of other things to put your self on the network securely.

Seriously, unless you are in the very early stages of development, such a radical move will be very expensive and time-consuming, and, in many cases, far more expensive than it's worth. It's not reasonable to expect an organization to make such a radical change overnight. We hope cooler heads will prevail.

Here are critical steps you can take to minimize and handle successful intrusions that have nothing to do with the technology deployed on your network.

  • Make a living security policy effort. If your security policy is collecting dust on a shelf, it's worthless. Start anew, involving people from all key departments. Figure out how your security policy can support your business plan while increasing your security stance.

  • Institute an incident-response plan. Knowing who is responsible for what, knowing when to call in outside help, and knowing what steps to take to minimize your exposure and damage will provide everyone involved with a plan of action. The last thing you want to do is make snap decisions during a crisis.

  • Have a disaster-recovery plan -- even to the point of figuring out how to rebuild critical systems in the event of catastrophic loss.


    Survivor Intro | Security | Network & Systems Management | Mobile & Wireless Technology | Digital Convergence | Service Providers & Outsourcing | Business Applications | Infrastructure | Data Management & Storage | Corporate Profiles | Letters | Full Nelson | The Inside Story

  •    Page: 1 | 2 | 3 | 4 | First Page





    Ready to take that job and shove it?

    Function:

    Keyword(s):

    State:
    SPONSOR
    RECENT JOB POSTINGS
    CAREER NEWS
    Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

    Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










    InformationWeek U.S. IT Salary Survey 2008
    Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
     
    ROLLING RIGHT ALONG
    Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



    Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








    TechSearch


    Microsite of the Week


    Powerful Information at Your Fingertips



    InformationWeek Business Technology Network
    InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
    InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
    Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
    space
    Techweb Events Network
    InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
    Black HatGTECEnergy CampMashup CampStartup Camp
    space
    Light Reading Communications Network
    Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
    Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
    space
    Financial Technology Network
    Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
    space
    Microsoft Technology Network
    MSDN MagazineTechNetThe Architecture Journal
    space
    App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
    About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
    Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights