by Paul Desmond

Intel IT takes layered approach to security

News
Aug 3, 20076 mins

Balance your needs, spread your spending and measure the results, advises internal Intel security expert.

Intel’s internal IT groups shares its layered approach to securing data.

In an era when more and more intruders are coming after corporate data for profit, not just for fun, a layered approach to security is more important than ever. The approach must be built on sound policies that are effectively communicated throughout the organization and backed up with spending on the right controls, but not too much spending in any one area.

In a nutshell, that’s the philosophy that Intel’s internal IT group follows to protect the company’s own considerable corporate assets, according to Michael Sparks, senior security specialist with Intel’s Technology Information Risk & Security group.

In his talk at the recent Network World IT Roadmap Conference & Expo in Santa Clara (Learn about our Dallas IT Roadmap slated for Sept. 6), and in a follow-up interview, Sparks warned that we are now facing third-generation cyber attacks. Whereas first-generation attacks were launched mainly by those looking for some measure of notoriety, the motive shifted in the mid-1990s with second-generation attacks that sought to bring down corporate computers. Today, the motive is financial gain and the target is data, whether personal data such as credit card numbers or corporate intellectual property, either of which can be sold for profit.

“If people are getting paid for it, they’re going to go where the money is,” Sparks says.

In his talk, Sparks described the current security climate as a “perfect storm,” in which threats – meaning people – continually try to exploit known vulnerabilities in computer systems. This combination represents a risk to business assets, including confidentiality and integrity of data, and loss of the data itself. So the business must implement some form of control to protect itself, such as antivirus software, an intrusion-detection system or encryption. No sooner is one control implemented than a new vulnerability crops up, starting the cycle all over.

The regulatory climate adds to business risk, because public companies such as Intel must comply with the Sarbanes-Oxley Act as well as California’s database breach disclosure law. Such regulations can pull security budget dollars away from areas that the company may want to protect by forcing them to instead spend money on areas they are legally bound to protect, Sparks says.

What results is a balancing act, in which the company must weigh its need to provide authorized access to data on one side vs. the need to protect its assets on the other. “What you really want to do is research your requirements, your needs and what you’re trying to protect and put the greatest effort into that,” Sparks says. Companies must be mindful, however, that if they err too far on the side of caution, they may limit the usefulness of their most important asset: their data. If employees who need data can’t get at it, the data does the organization no good.

With its huge constituency of users to think about, as well as significant legal requirements to meet, Intel tends to fall just to the conservative side of the equation, Sparks says. The idea is to keep information assets reasonably protected, and to keep legal, but still allow information to be available to those who need it.

A 4-pronged approach

Once you determine where you want to fall on the security spectrum, the next step is to implement a layered approach to ensure proper protection. Intel came up with four layers: Policy; training and education; technology and testing; monitoring and enforcement.

In terms of policies, they must be formulated such that they mesh with business goals, which means management has to be involved in the process. The legal department likewise has a say in terms of what regulatory issues must be dealt with.

The next step is to publicize the policies and to train users on what is expected of them. “Set the expectations, document the expectations and make sure that your employees or others who handle data realize they’re accountable for the protection of that data,” Sparks says. “If your HR people don’t know they need to protect your personal data, how are they going to do the right thing?” Training is also the only way to educate employees about social engineering and phishing attacks.

Training can take many forms and must be constantly reinforced. Intel uses its company newsletter to reinforce the policy message, recounting examples of when security breaks down and the damage it can cause. It also has a series of posters with security reminders that it posts in public areas.

When it comes time to implement technology to help provide security, Intel strives for efficiency in terms of the dollars it spends. The greatest increase in security effectiveness comes with the initial investment you make in a given security technology, Sparks says. But as you spend more money on any particular counter-measure, your rate of risk reduction per dollar slows down. For each security technology, you reach a point where it no longer makes sense to continue investing in that technology, because shifting those same dollars to another technology will give you a better return on your investment. In short, it’s better to spread security dollars across many counter-measures, just as financial advisers recommend reducing risk by spreading investments among different types of stocks and bonds.

“You have to sample the environment and ask, ‘Are the controls we’ve implemented doing what we expected?’” Sparks says. Intel periodically conducts a “war game” against itself to find weaknesses – before somebody else does. Rather than use outside professionals, Intel uses its own personnel to conduct the war games, but always with management approval. And of course it’s imperative to keep the results close to the vest, ‘lest someone outside the company find out about your weaknesses before you have a chance to correct them.

The last step is to implement tools that allow you to constantly monitor your environment to look for not only attacks in progress, but security policy violations. Such violations should have consequences that are appropriate to the action, ranging from an automated response alerting the user to the violation to a phone call from a manager.

Targeted threats

This type of layered defense is more important than ever because of the changing nature of cyber threats. While many Internet criminals currently target consumers, Intel believes businesses will increasingly become targets because they have lots of valuable data.

Additionally, the attacks are targeting more than just PCs; anything with a computer chip and software that holds potentially valuable data is a target. “If you’re using a smart phone, they’re going to attack that if there’s anything of value for them, whether it be the use of your system without your permission or the data that’s on it,” Sparks says. “Is it personal data or competitive advantage information, and what measures will protect it?”

Desmond is events editor for Network World and president of PDEdit, an IT publishing company in Southborough, Mass. He can be reached at paul@pdedit.com.