home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers




Your Network's Not Ready for E-Commerce

By Brian Walsh  A first-time e-commerce project manager informs management that after due diligence, package selection and integration, enabling the company's Web site for e-commerce will take six months and cost approximately $400,000. He then notes that the only thing left to do is to inform the network group. But what can the network group really add to the project, he wonders? Maybe a new T1 line? Well, he has already budgeted for that, to the tune of $1,000 per month and 30-days' notice to install. All in all, he anticipates no problems.

The lies we tell others are bad, but it's the lies we tell ourselves that really get us into trouble. The reality is that security is hopelessly lacking on internal segments behind the firewall, which could cause our project manager's figures to grow by half, or even double, by the time the project is completed.

Introducing e-commerce to an organization exposes quite a few of these little lies. You've heard them: "Our firewall protects us from the Internet." "Since the Web server is in the DMZ (demilitarized zone), we don't have to worry about it." "Our internal systems are secure." "We don't have anything worth hacking." "Security is a network problem." And my favorite, "Our production systems are flexible because they're based on standards." What a panic! It actually would be funny if not for the time and money involved.

These lies contribute to the security rationalization concerning network deployment behind the firewall. The architecture of internal segments is driven by several factors: historical accident (we needed it, we added it), performance (based on user complaints, we moved the servers to their own segment) and/or reliability (someone will get fired if there's a problem with this application, so we'll buy two of everything). Rarely has security been the driving factor in the tactics of network architecture and, consequently, the firewall is often the only secure part of your network. E-commerce just happens to be the first application to demand the same degree of security behind the firewall as is traditionally applied to the DMZ.

Making Myths Web server host security is enough for e-commerce, right? Wrong. Although Web application folks and project managers often believe this myth, the truth is that no matter what security scheme you've employed to protect your Web content, it won't be good enough for e-commerce. However, those of us in the networking space must also shoulder some blame. See, the project manager remembered what you said in passing last year, "Our Web server is secure." And, of course, the project manager then assumed that your statement applied to any Internet application. You then supported that implication by not explicitly stating, "But our internal systems A through Z are not secured."

Essentially, the problem is that the e-commerce initiative everyone in IT is so jazzed about will touch practically every application and database in your shop. Gone is the luxury of defending only a single segment. That innocent Web server will start opening sessions to servers on all of your production segments. Take heed: Do not respond to this challenge by questioning, "Well, can't we just duplicate all that data onto servers on the DMZ?"

Until now, your firewall has served as "a hard crunchy shell around a soft chewy center." (Thank you Bill Cheswick, Bell Labs, Lucent Technologies, for the imagery.) I know, I know--administrators look after all the servers, and you've distributed a security policy to all your personnel. However, if the thought of a server on your DMZ opening a session with a server on an interior segment fills you with dread (because once hackers have access to the production segment they can traverse all segments at will), how do you define usable, flexible security? E-commerce is more than just selling online; it gives your customers and partners access to some of your core data and applications.


Related Links

Inside Outsourcing
August 1, 1998

The 'Q' In QoS Stands For Quality
September 1, 1998

Building a Business Plan for an E-commerce Project
September 15, 1998

Is 'Good Certification Program' an Oxymoron?
October 1, 1998

The Once and Future Development Standard
November 1, 1998


Other Columnists

Top of the Stack
By David Willis
On the Edge
By Art Wittmann

Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page


e-mail E-mail this URL






Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media Limited  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights