Two IT security pros share advice on getting vendors to work together
When there’s not quite the right fit in network security gear to meet your needs and goals, you might wind up settling for some distant second choice, if one exists. But enterprise technology managers are proving you can get what you want by pushing vendors to innovate — a trend that may be growing because of the economic downturn.
When there’s not quite the right fit in network security gear to meet your needs and goals, you might wind up settling for some distant second choice, if one exists. But enterprise technology managers are proving you can get what you want by pushing vendors to innovate — a trend that may be growing because of the economic downturn.
Tony Lucich, chief information security officer (CISO) and enterprise architect for Orange County, Calif., and Mark Starry, manager of enterprise architecture and security for Concord Hospital in New Hampshire, each hit a few roadblocks during some recent security projects. There were incompatibilities between switching and security gear, or security products fell short of accomplishing exactly what was desired. But Lucich and Starry, who don’t know each other, share a spirit for overcoming obstacles by getting vendors to innovate to help their organizations.
Some analysts say this willingness to accommodate customers’ special needs happens less often in the good times when fat-and-happy vendors will be complacent, but when the bad times arrive, customizing is a way to grow market share. “This ‘responsiveness’ to customers is most important in downturns like we are in now,” says Gartner analyst John Pescatore, noting the smaller vendors often take the lead in this regard.
For Starry at Concord Hospital, the basic challenge was finding the means to comprehensively monitor the complex, high-speed network put in place based on Nortel core routing switches and trunking to link healthcare facilities in its New Hampshire locations to share high-speed IP traffic, including voice over IP.
While Concord Hospital already had IBM’s Internet Security Systems intrusion-detection and protection systems at the perimeter, this gear wasn’t the right choice for monitoring the entire internal network. Starry says that was mainly because the Nortel network, with its Routed Split Multi-Link Trunking, is so good at eliminating bottlenecks, it made collecting security-related information related to packet flows harder to collect, too.
Starry began a hunt to see what kind of security-monitoring equipment might be out there that could work inside the new network, narrowing down a short list that included Mazu, Q1 and Lancope. But no vendor seemed to support Nortel’s proprietary protocol. Rather, Cisco’s version of NetFlow was the norm.
But Starry didn’t give up. He discovered that Lancope was willing to update its StealthWatch network behavior analysis monitoring gear to support Nortel, and he brought Lancope engineers together with Nortel ones to make it happen. This didn’t come cheap: Starry says there’s so much additional stress put on switches made to export every session out to a security collector that the switches had to be boosted with special hardware cards that cost upwards of $100,000.
But the month-long development work — which helped Nortel correct a bug in its code — was successful, and the security monitoring is working as envisioned, identifying unwanted applications and network usage, Starry says. “With Lancope, we can tell if someone is trying to access that fund-raising server, for instance,” says Starry, noting the comprehensive internal monitoring is a requirement to meet the demands of audit committees.
Orange County’s e-mail encryption plan
For Lucich, the CISO and enterprise architect for the Orange County government, the issue was finding security vendors in the encryption and e-mail security arena to help meet the requirement that the county’s 23 agencies, with their 24,000 or so employees, encrypt e-mail containing sensitive data, such as Social Security numbers or financial information.
Lucich says after a review of encryption possibilities, the county favored the public-key certificate system in Voltage Security’s SecureMail, which doesn’t require digital certificate distribution. But the county needed to find a way to send all the county e-mail through a common point to be subject to content inspection, as well as blocking inbound spam.
For that, Lucich favored Secure Computing’s IronMail appliance (Secure Computing is being acquired by McAfee). Ideally, the county wanted the Voltage SecureMail server and the IronMail gateway appliance to work in harmony so that IronMail could make the decision to encrypt at certain times even if the county employee had failed to do that manually.
Lucich says he encouraged Secure Computing to figure out how to integrate IronMail with Voltage’s SecureMail digital-certificate server and required them to show that was possible before finalizing a contract.
The result was what he wanted, Lucich says: “The true policy engine is in IronMail, which has to scan to decide whether to encrypt. The encryption is with SecureMail because we wanted key management the way Voltage did it.” Since the e-mail encryption process went live in June, about 25% of Orange County employees have been trained on how the security method works.




