Skip Links

Network World

  • Social Web 
  • Email 
  • Close

EMC CSO shares lessons learned from protecting storage giant

EMC encrypting all its laptops, relying heavily on security information management
By Bob Brown , Network World , 01/17/2008

As if Roland Cloutier doesn’t have enough of a challenge protecting a business the size of EMC, consider that the $11 billion storage and information management company also bought security pioneer RSA last year. How bad would that look if EMC suffered a major breach?

Cloutier, who is CSO of EMC’s Global Security Organization, told a group of other high level IT executives earlier this month at a Center for Information Management Studies seminar at Babson College in Wellesley, Mass., that such pressure forces EMC to have a superior business protection plan. Part of that includes encrypting every EMC laptop, turning them into paperweights in the hands of anyone other than the owner.

Cloutier shared lessons with the audience learned from his time at EMC and before that in law enforcement and other security-related jobs.

He emphasized that security can be valuable to a business beyond keeping IT systems up and running.

“I challenge the theory that [security] is a necessary evil and I believe that if you do security well as part of your business processes that you will become a more competitive company,” Cloutier said.

Security affects businesses in many ways, he says, from the downstream impact on customers to the ability to comply with regulations such as the Sarbanes-Oxley Act.  

For EMC, the downstream impact of doing security well or not is on the security of its customers’ networks. One threat would be criminals trying to make changes to the manufacturing process for the software code to gain a backdoor into EMC products, Cloutier said.

EMC puts lots of emphasis on making sure its 40,000-plus employees are appropriately credentialed, part of its strategy for addressing workplace violence prevention, including defense against terrorism. Cloutier said 65% of all terrorist acts globally over the past three years were targeted at businesses, not governments. Offering protection is key to making employees happy and enabling them to work in countries where other companies might not feel comfortable having people work.

Another lesson shared was that forming a converged security organization -- one that includes both physical/corporate security and information security -- will pay off.

The benefits include having a common strategic vision and centralized metrics (many of which EMC has designed itself after looking at standard ones that don’t quite fit its business model) that can be used to spot trends across the organization. In the past, for example, the corporate investigations team spent lots of time investigating intellectual property theft and requested information from the IT team, but wouldn’t say why. Now, by working together, the IT team can see if people are leaving the company with IP and put a stop to it, Cloutier said. The consolidation also enabled EMC to eliminate redundant efforts, such as in forensics.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Whitepapers

Advancing the Economics of Networking

Aging network systems and old habits have dictated how businesses spend their IT budgets. As a...

Implementing HA at the Enterprise Data Center Edge to Connect to a Large Number of Branch Offices

This paper reviews the problem of creating a network where the dynamic availability of services is...

Enterprise Data Center Network Reference Architecture

Using a High Performance Network Backbone to Meet the Requirements of the Modern Enterprise Data...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Stay out of the headlines: Detecting and preventing network intrusions

How do YOU stay out of the headlines? There is no denying that risk exists in our computer-driven...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

IP address management in 2008 - six things to know

Read this Network World Special Brief to learn how Enterprise IT managers must update their...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...