Adam Ely

Network Computing Blogger

Tags: , ,

Channel: Security, WAN Security, Data Protection

See more from this blogger

Know Your Product's Security Capabilities

To build-out enterprises we utilize technologies in all forms. From the routers that shape the network to interrupters that understand the software powering our web servers, third parties have a hand in how secure our enterprise is. It is important when selecting third party technologies that security be kept in mind but we don't always get much of a choice. If we need a desktop operating system, we are pretty limited. If we need a widget for our website, however, we have more options.  No matter the technology, ask the questions that matter to you around security. While you may not get all the answers you want, you will at least understand the risk better and be able to make better solutions in the long run.

Recently, I had to review a product from a vendor. There was only a handful of players in the highly specialized space, and only one vendor who could offer what we needed. I was fortunate that they had thought about security and met most of the requirements I had for this technology. The requirements they couldn't meet were less of an issue since I at least understood what they could and could not do. Even though the risks couldn't be eliminated, by understanding the risks I could work to mitigate them. This is the approach I took with a business intelligence package that was very good for reporting upon large amounts of data but was designed poorly in regards to security. The application was to be the core of our reporting platform offered to customers, and it way outperformed the other vendors we evaluated. By knowing the issues we were able to implement controls to overcome the package's deficiencies.

A blog post from Amorize application security and malware experts details how thousands of websites have been serving malware via a widget created by Network Solutions. This is a good example of a technology that should be vetted, is not mission critical, and there is most likely another vendor offering a similar solution. The website widget is a small, common example that illustrates why you should be wary of the technologies being introduced into your environment and understand the risks they pose.

When approaching a vendor to discuss the security of the product, don't be surprised if they are defensive, attempt to deflect your questions, or even try to stonewall you.  Ensure them that you are just trying to fully understand the pros and cons and how you can implement the solution to best fit the needs of your enterprise. Remind them security is important to your business, and to theirs, and that you are not on a witch hunt, just educating yourself. Unfortunately, not all people are as understanding and realize security due diligence is a good thing, but don't fault them for their short-sightedness and attempting to protect their business unless they are being outwardly dishonest. Ask the questions that matter to your business and are related to the product being reviewed. If the product will never touch healthcare information, then don't put them through HIPPA questions. Ask targeted questions based on the risk the product poses to your organization.

By knowing how a vendor handles security, you will better understand the risk it poses to your organization and what extract work maybe required to ensure it meets your security requirements. Just because it doesn't meet all requirements out of the box doesn't mean it should be dismissed. Review and make an educated decision with all the facts.

Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

WAN Security Reports

Research and Reports

Storage Virtualization Guide
May 2012

Network Computing: May 2012

TechWeb Careers