The security imperative
By Stacy Collett
,
Computerworld
, 12/30/2008
- Share/Email
- Tweet This
- Print
Leslie Lambert, vice president and chief information security officer at Sun Microsystems Inc., returned from a three-week business trip to India with a few souvenirs and a whole new set of IT security priorities for
2009.
India is home to 29 of Sun's 250 managed services providers. Economic troubles there have made it harder for those providers
to build out their data centers, so they're procuring services from other providers around the globe.
"I'm going to be shifting focus," Lambert says. In 2009, projects like server security, metrics, application security and
Web security will likely take a back seat to new data-protection measures and deeper enhancement of user-access and identity
management systems. "Those are the big hitters now," she adds. In a steadier economy, all of the projects would likely have
gone ahead, she says.
Indeed, security remains a top priority for all companies -- with antivirus, encryption and identity management topping the
list for Computerworld 's Forecast survey respondents. But with economic uncertainty overshadowing most IT budgets, managers
will have to pick and choose the projects that are most important.
The U.S. Tennis Association (USTA) is a prime example. The organization generates 85% of its revenue in just two weeks in
late summer during the U.S. Open tennis tournament, and with so much riding on one event, the IT staff can't afford any security
snafus. So when CIO Larry Bonfante decided the USTA would need to upgrade its network access control system to protect the
network from contaminants brought in by 800 media members using its Web site, the project got a green light, despite a flat
budget.
"Anything that can impact revenue, the fan or customer experience, or the game of tennis is considered business-critical,"
Bonfante says. Still, "all projects are certainly under significant scrutiny to make sure there's a tangible return on investment
before we get funding for them. Security projects are no different in that regard."
Law firm Nexsen Pruet LLC plans to overhaul its intranet in 2009. Among other things, the upgrade will enable the system to
grant users access to financials and reports according to their security levels. Despite the tough economy, the project will
move forward, but at a slower pace than originally planned. "Increasing overall organizational efficiency and productivity
sometimes means increasing spending for technology infrastructure and key applications," says Technology Director John E.C.
Davis.
Keeping your guard up
Projects that "keep the bad guys out" are usually the most recession-proof, says John Pescatore, an analyst at Gartner Inc. But spending for projects that "let the good guys in" is often tied to business cycles.
"If there's a new business project to open up new services and products, there's a lot of security spending in identity and
access management," says Pescatore. "But in 2009, that's probably the area we'll see get hit," creating a growing potential
for security leaks.
For more enterprise computing news, visit Computerworld. Story copyright Computerworld, Inc.
Partner Content
Blue Stripe Software
www.bluestripe.com/
Improving Application Performance Troubleshooting
Diagnosing why an application is slow is hard, at times taking days or weeks to isolate and resolve. This paper explains the challenges involved using current management tools, provides a 'wish list' for application management and analysis, and explains the need for an application system-wide approach that monitors entire applications, not components.
Download Whitepaper
Virtual Vigilance: Managing Application Performance in Virtual Environments
This paper highlights the impact of virtualization on application performance. "Managing Application Performance in Virtual Environments" states: "Best-in-Class organizations are predominately taking actions around improving visibility across both physical and virtual systems, assessing the business impact of application performance and understanding interdependencies of applications in virtualized environments."
Download Whitepaper
Application Service Requests: The Missing Link for Pragmatic ITSM
Forrester Research analyst Glenn O'Donnell and BlueStripe co-founder Vic Nyman discuss a breakthrough approach to application problem management. Learn the new approach for ITSM problem management, which provides: Rapid isolation of application slow-downs to specific components for quick problem resolution, 24/7 monitoring for proactive notification of potential issues before end users are impacted and much more.
Register for Webcast
Comment