Skip Links

Network World

  • Social Web 
  • Email 
  • Close

5 critical security questions that IT and corporate leaders are asking

Getting the answers to who, what, when, where and why regarding network security
Technology Executive Alert By Linda Musthaler and Brian Musthaler , Network World , 01/28/2008
Musthaler
Sign up for this newsletter now!

Who, what, when, where, and why? When it comes to network security, these are the five critical questions that IT and corporate leaders are asking. As pressure mounts for companies to protect their information assets from unintentional disclosure and to maintain compliance with a growing number of policies and regulations, it’s becoming more important to know exactly who is doing what on the network as it is happening.

While only a human can answer the question of “why?” numerous tools individually help organizations manage and answer parts of the “who,” “what,” “when” and “where” questions. Tools like intrusion detection systems (IDS), security information management (SIM), network access control (NAC), and network behavior analysis (NBA) all provide good details that paint portions of a picture. The complete picture, however, is like one of those connect the dots drawings; the details are all there in different silos (e.g., users, assets, applications), but sometimes additional resources are required to match/reconcile results to reveal the picture in its entirety (Learn more about IDS products from our Intrusion Detection Systems Buyer's Guide; Learn more about SIM products from our Security Information Management Buyer's Guide; and Learn more about NAC products from our Network Access Control Buyer's Guide).

This is the premise behind the user identity-based monitoring and verification of Securify. An appliance called a Securify Monitor tracks all post-connection networked transactions to users to provide a view of "who" is accessing "what" applications and "where" in the network. The user identity and group / role associations are dynamically drawn from existing user directories (Learn more about identity management products from our Identity Management Buyer's Guide).

The Securify tool has two main functions: automated discovery of actual user activity and usage of business systems, and automated verification to validate that the user activity is permitted within the role-based controls and pre-built security best practice templates you’ve set for your systems. The appliance brings all the information together in one place, and you can view prioritized violations with user identities and incident details via an intuitive Web interface – as they are happening.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (2)
Login
Forgot your account info?

No one paidBy Linda Musthaler on January 30, 2008, 9:37 amSorry, fastrev, no one paid us to write this article. Not Securify, and not even Network World. Thanks for the suggestions for the other vendors to follow-up with....

Reply | Read entire comment

RE: 5 critical security questions that IT and corporate leaders are askingBy fastrev on January 28, 2008, 1:38 pmWOW just rename the title "The Securify solution" paid for by Securify Many products do the same thing... Mazu, Lancope, Arbor and Q1Labs all are more welknown...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous

Join the Discussion