Skip to main content
It’s That Time Again.

A large balloon hangs over West London, pointing the way to this year’s Infosec Show and with it the hanging promise or perhaps more accurately, the faint hope of better information security in 2004 than was available a year earlier.

Last year, when I wrote a long and detailed eGov monitor and Computer Weekly sponsored ‘Special Report’ on information security to coincide with the Infosec show, I was reminded of the final scene of Monty Python’s ‘Life of Brian’, and the chorus singing, “Always look on the bright side of life”. After all and like the movie, it was a year of few choices, “Crucifixion or stoning”? Blaster or Sobig and sadly, a great deal more besides.



This year doesn’t promise to be any better in the information security space and the industry appears almost frantic in its search for new ideas and new technologies to plug the gaps which continue to appear, week in and week out.

In the last six months, Microsoft’s constant patching process has improved, almost out of recognition but the broader vulnerability problem among the population remains a serious cause for concern. While larger businesses have invested significantly in every aspect of network security, the evidence of the most recent surveys from the DTI and others, suggests that smaller SMB and consumer customers continue to ignore the risks and the messages and take inadequate content security measures.

However investment alone doesn’t offer a silver bullet in the fight against computer crime. This year’s 2004 DTI survey expresses real concern that businesses without the right monitoring and intrusion prevention processes in place may be operating under a false level of comfort, in that scanning and hacking activity may not be detected until it is too late to react. While seventy-two per cent of businesses expressed confidence in their technical processes and ability to prevent or detect security breaches, the research speculates that on the evidence, such confidence might be misplaced

While many IT professionals believe that Linux is more secure than Windows, encouraging them to consider introducing the Linux OS when they might not have done in the past, the true picture of what works best and what doesn’t remains complicated. The platform diversity suggestion offered by Gartner in October of last year has yet to find any popular following and more effort appears to be concentrated on ‘hardening’ existing environments than introducing new ones. After collecting a year's worth of vulnerability data, Forrester Research has concluded that both Windows and four key Linux distributions can be deployed securely with key metrics that include responsiveness to vulnerabilities, the severity of vulnerabilities, and efficiency in fixing flaws

Risk and the part it plays in the wider information security picture is where the real action appears to be this year. The challenge of ‘Embedding security and designing-out’ risk has emphasised the critical importance of perimeter security as a first line of defense against attack in a much wider, distributed security model, which embraces client, server and the extended network.

‘Put not your faith in boxes’ but 2004 is also the year that many companies finally realised that a managed firewall is where security starts and not where it ends. This year and having finished a short tour with Gartner analyst, Dr Gordon Frank, there’s an emphasis a more complete security approach, one that includes a firewall but embraces , anti-virus, security policy and many different solutions capable of integrating dynamically with network directories and authentication servers and know as Intrusion Prevention Systems.

Finally, one of the best security tools I’ve seen in 2004 so far is a book from Microsoft, titled “Protect yourself online”. My own recommendation for a peaceful year ahead is for the company to make it available to anyone who wants it at cost. It might even knock Harry Potter off the bestseller list but if it in anyway helps better secure the wide-open consumer broadband and SMB sector, then the rest of us in business will feel the benefits.



Comments

Popular posts from this blog

Civilisational Data Mining

It’s a new expression I haven’t heard before. ‘Civilisational data mining.’

Let me start by putting it in some context. Every character, you or I have typed into the Google search engine or Facebook over the last decade, means something, to someone or perhaps ‘something,’ if it’s an algorithm.


In May 2014, journalists revealed that the United States National Security Agency, the NSA, was recording and archiving every single cell-phone conversation that took place in the Bahamas. In the process they managed to transform a significant proportion of a society’s day to day interactions into unstructured data; valuable information which can of course be analysed, correlated and transformed for whatever purpose the intelligence agency deems fit.

And today, I read that a GOP-hired data company in the United States has ‘leaked’ personal information, preferences and voting intentions on… wait for it… 198 million US citizens.

Within another decade or so, the cost of sequencing the human genome …

The Nature of Nurture?

Recently, I found myself in a fascinating four-way Twitter exchange, with Professor Adam Rutherford and two other science-minded friends The subject, frequently regarded as a delicate one, genetics and whether there could exist an unknown but contributory genetic factor(s) or influences in determining what we broadly understand or misunderstand as human intelligence.

I won’t discuss this subject in any great detail here, being completely unqualified to do so, but I’ll point you at the document we were discussing, and Rutherford’s excellent new book, ‘A Brief History of Everyone.”

What had sparked my own interest was the story of my own grandfather, Edmond Greville; unless you are an expert on the history of French cinema, you are unlikely to have ever hear of him but he still enjoys an almost cult-like following for his work, half a century after his death.

I've been enjoying the series "Genius" on National Geographic about the life of Albert Einstein. The four of us ha…
The Mandate of Heaven

eGov Monitor Version

“Parliament”, said my distinguished friend “has always leaked like a sieve”.

I’m researching the thorny issue of ‘Confidence in Public Sector Computing’ and we were discussing the dangers presented by the Internet. In his opinion, information security is an oxymoron, which has no place being discussed in a Parliament built upon the uninterrupted flow of information of every kind, from the politically sensitive to the most salacious and mundane.

With the threat of war hanging over us, I asked if MPs should be more aware of the risks that surround this new communications medium? More importantly, shouldn’t the same policies and precautions that any business might use to protect itself and its staff, be available to MPs?

What concerns me is that my well-respected friend mostly considers security in terms of guns, gates and guards. He now uses the Internet almost as much as he uses the telephone and the Fax machine and yet the growing collective t…