Career Education Corp. gets smart on IT security
Security information management earns this education services company top grades in threat assessment and control, plus Sarbanes-Oxley compliance
By
Denise Dubie, Network World
November 26, 2007 12:10 AM ET
- Share/Email
- Tweet This
- Print
When Michael Gabriel joined Career Education Corp. in February 2004, he knew he needed a business case to justify an overhaul
to the educational services company's information security program. Looming Sarbanes-Oxley Act (SOX) compliance deadlines
provided just that for the CISO, but that initiative was only the start of a thorough security management program that continues
to this day.
CEC, in Hoffman Estates, Ill., had grown tremendously over the previous five years, becoming what in 2004 was a $1.7 billion
company. Following this boom, it needed to formalize controls and get a handle on its security infrastructure to enable uninterrupted
growth going forward, he says.
"The immediate need was [SOX], but when I did further analysis . . . the remediation projects that needed to get done ran
the gamut from security policy to change-control to incident-response awareness and security monitoring," Gabriel says.
CEC earns its place among the 2007 Enterprise All-Stars for its smart adoption and implementation of security information management (SIM) technology. With netForensics' nFX Open Security Platform (OSP) Version 3.4 software, CEC automates
security and other logs from some 10 firewalls, 10 prevention systems, 12 domain controllers and all Cisco devices. In addition, by integrating Rippletech's RippleTech Informant Version 1.0 into the netForensics rollout, Gabriel
can collect logs from six Microsoft databases. No software on the actual data source is required.
Among the many benefits of CEC's estimated $400,000 investment are SOX compliance and comprehensive reporting, combined external and internal threat management, improved security-threat response time, and
increased ROI on IT resources. CEC invested $100,000 to $200,000 initially in the security-management software and plans to
add another $100,000 to $200,000 later this year to augment the project and expand to a second data center.
"It's hard to quantify in hard figures, but if we had not been able to use this technology we would have had to invest in
a systems administrator to do this work; and from a security standpoint, we wouldn't have such visibility into our entire
environment," Gabriel says.
Gabriel started at CEC during what he describes as a whirlwind. "There wasn't a lot of time to do extensive bakeoffs. I needed
to get this project underway," he says.

Fortunately, Gabriel had heard from peers about SIM products from such vendors as ArcSight and netForensics. Because scalability
was a top concern, he decided on netForensics, which had a proven success record in large government environments. The vendor's
back-end capabilities -- large-volume data-collection and -correlation -- resonated with him. He says he would pass on a pretty
GUI in favor of power on the back end any day.
It's not that netForensics, which has just added a collector for Microsoft Windows platforms to its product portfolio, didn't
have a good GUI. Gabriel found the product most accurately addressed CEC's needs, especially considering the fortuitous addition
of the Windows module. "We were one of the first customers for that," he says.
Comments (6)
ya, right.By cec_employee on November 26, 2007, 3:35 pmMichael Gabriel must know someone at Network World. He also seems to have plenty of time to sell himself via press releases. This article is full of misinformation...
Reply | Read entire comment
I think someone should askBy Anonymous on November 26, 2007, 9:56 pmI think someone should ask Gabriel for the results of all these implementations because not a word of this actually happened. I won't bad mouth the products as I'm...
Reply | Read entire comment
Made up bs like this is oneBy Anonymous on November 29, 2007, 3:27 pmMade up bs like this is one of the main reasons I left. Even though I have been gone for months I can assure you this article is pure fiction.
Reply | Read entire comment
Important to knowBy The Guy who set the Security Servers Up on December 7, 2007, 12:40 pmThe important thing to know when you read articles is the head of the department will always get credit for what has been approved for installation in an environment...
Reply | Read entire comment
Heads of Departments Should Always Give CreditBy Anonymous on December 11, 2007, 4:49 pmTrue leaders always make sure to give credit to the people that did the work. Not doing so is the same as publishing and not citing your sources.
Reply | Read entire comment
Who cares?By Anonymous on June 5, 2008, 10:23 amEveryone is trying to figure out what will happen next? Will they outsource the Data Center? Will they sell the current Data Center in Elgin? IT members are leaving...
Reply | Read entire comment
View all comments