home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






Background news analysis

Tackling Network Security Can Be An Uphill Battle

By Christy Hudgins-Bonafield   No doubt about it: Security is hot. The Computer Security Institute says security staff budgets rose 100 percent over the past seven years, and it forecasts an additional 18 percent rise this year. Nevertheless, securing networks is devilishly difficult--largely because security solutions tend to consist of one part product and three parts

policy. Juggling corporate politics, procedures, staff requirements and budgets in order to secure a network can make a network manager feel like Sisyphus in Hades.

Mercifully, according to a cadre of usually cynical security gurus, a new breed of product may cool the heat. Users of NetRISK, formally introduced in March by Trident Data Systems, s ay it is the first rules-based risk-assessment tool for networks. It also may be the first tool to incorporate corporate-specific network and intellectual property assets into risk assessment equations. That tally also estimates the overall cost to the user based on various procedures and the price tag on security products.

Jack Michalek, senior information security engineer at defense security consultancy Data Systems Analysts in Fairfax, Va., says NetRISK is "light-years" ahead of anything else on the market. Michalek says NetRISK let him cut a two-week job for a commercial client to three days, and he thinks most large businesses would be able to cut risk-assessment time in half.

Trident officials say its product, originally conceived as part of a U.S. Air Force-commissioned manual risk-analysis process, has been widely accepted as the risk-assessment model for the Department of Defense's commercial and information warfare traffic. In March, some of the world's largest accounting consultancies, telep hone companies and systems integrators were exploring the automated version of the software or usi ng it with clients.

The Process, the Limits With NetRISK, IS managers can train subnet managers to describe network assets--and their business value--in a database, whether the asset is Coke's secret formula or a specific hardware platform or operating system. A network map unites the assets, which are assessed for risk against a regularly updated Trident database of 250 threats.

Companies are biting. In March, AT&T was already one month into the largest risk assessment it has ever undertaken as an outsourcer, using NetRISK to evaluate security for a Fortune 100 company. David Gore, a member of AT&T's secure systems engineering department, says AT&T will consider using NetRISK itself if it can customize the tool with Trident's assistance. Gore also anticipates interesting future enhancements. For example, by late summer Trident plans to accelerate network drawing and cut-and-paste tasks and provide a first-phase autodiscovery tool to help users create network maps. Trident also is evaluating integration with asset management tools.

Small-to-midsize companies could stumble over NetRISK's $38,200 price tag. But AT&T's Gore says these companies often outsource such tasks and the cost of outsourced risk assessments will plummet if the company performing the assessment can pare the number of hours necessary for the job, as is possible with NetRISK. Trident officials add that NetRISK cuts asset-collection time by establishing strict definitions and rules for clustering asset groups into categories. For example, after a training period in asset collection via NetRISK, engineers and network security staff can list assets, either developed themselves or drawn from a standardized list. They then forward this work to the CIO for an overall risk assessment. The risk-assessment database can be updated whenever equipmen t is added or more vulnerabilities occur.

The H-Report
News, Trends and Analysis
by Kelly Jackson Higgins
Internet
H.323 Comes to Multipoint
by Christy Hudgins-Bonafield


Updated April 24, 1997








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights