IT Roadmap: After years ignoring network security, Harvard Business School makes it a priority - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Crackin' the Kraken bot. Listen now!

Network World's Newsmaker of the Week

Wireless dangers at airports. Listen now!

Network World Panorama

Additional Resources

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

HP Live Webcast: Create a more efficient NOC HP

HP's Network Lifestyle Management can help you automate network processes and improve NOC efficiency. This webinar is part three of a four part series on Business Services Management (BSM) evolution to help you better align IT with business objectives. Register for this event scheduled for Wednesday, January 30, 2008 at 11:00 a.m. PDT/2:00 p.m. EDT to learn more. Register for this live webcast now.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

So the line of defence remains is "PIN NUMBER" Wowww what a strong security ? HSBC , invest some money...- Anonymous

Join the Discussion

IT Roadmap: After years ignoring network security, Harvard Business School makes it a priority

Security for applications becoming more important, analyst says at IT Roadmap.
By Jon Brodkin , NetworkWorld.com , 03/08/2007
  • Social Web 
  • Email 
  • Feedback 
  • Close

When John Arsneault arrived at Harvard Business School about five years ago, the school’s network was a hacker’s dream.

“There was absolutely no security in place from a perimeter standpoint, an application standpoint, nobody really knew what was going on. The reason for that was security was viewed as a philosophical issue vs. a technology and process issue,” Arsneault, the school’s director of network operations, said Tuesday at Network World’s IT Roadmap conference in Boston. “Prior to [my arriving] there was literally no virus software anywhere in the school, which I know sounds absurd, but it was true.”

Help desks were receiving 10 to 15 calls a day because of virus-infected computers, and denial-of-service attacks were frequent. Now it is rare for either one of those problems to occur, Arsneault said, because Harvard Business School has implemented security measures including a firewall, intrusion detection, and virus controls at multiple layers such as e-mail programs and desktops.

Before it became clear security was vitally needed, faculty members worried security measures would prevent the fostering of collaboration, an open environment and research, Arsneault said.

“What actually drove them the other way was the number of denial-of-service attacks and outages we had. Eventually that philosophical approach to security went away,” he said.

Arsneault spoke during a session titled “Application & Content Security,” in which analyst Andreas Antonopoulos warned that enterprises are barely focusing on security of applications despite the crucial data and processes stored on application servers.

As threats move higher up the seven-layer network protocol stack toward applications, security measures must also move up the stack, said Antonopoulos, senior vice president and founding partner of Nemertes Research.

“We have the crown jewels on the most vulnerable servers,” Antonopoulos said. “Threats have been moving closer and closer to the application stack. … I’m very concerned about the applications being deployed in enterprises with no consideration being given to security.”

1 | 2 | 3 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code