sandra_gittlen
Contributing Writer

Data security takes center stage

Feature
Apr 18, 20073 mins

Stan Quintana, managed-security services vice president at AT&T in Bedminster, N.J., agrees with Passmore that federation is critical to securing data moving across intranets and extranets.

Federation should be linked to a company’s network and data-management policies, he adds. A company that acquires five other companies can meld the policies and create a federation that lets them share data safely.

In addition to federation, the next generation of the Web will include a shifting from perimeter-based security to data-centric security, Quintana says. “We’re going to put security in place at a granular level to protect information itself,” he says.

The approach will be multipronged.

“I have to encode it. I have to ensure the access to that information — the keys — goes to the right people and is well managed. I have to make sure data is only useable on a need-to-know basis,” Quintana says.

Other factors include classifying data and making sure it can be distributed without being modified in flight. “Once you have all these steps in place, you’ll be able to open up your environment, because your data is safe,” he says.

In the future, all savvy companies will have a sophisticated digital-rights platform that will let them define and classify their information, as well as map it to appropriate users, Quintana says.

He also believes there will be universal authentication. Like Passmore, Quintana thinks that single sign-on, which has been promised for some time, will happen, and a central authority will hold a user’s credentials. These credentials will function as authorization for the corporate infrastructure and commercial entities. He says biometrics, such as an iris imprint, will be used in conjunction with other identifying factors.

Quintana also predicts that security will become a commodity and will be built into other services.

As infrastructure, such as servers and storage, grows exponentially, IT managers will give up handling all security problems themselves, he says. “I don’t think people realize today how hard it is to scale customer-premises-based security,” he says. “This is going to take everyone by surprise.”

He believes companies will realize the cost of internal security management in terms of risk, personnel and software, and subscribe to software-as-a-service in the core of the network.

“The magnitude of very sophisticated exploits — not just free-form viruses — is growing. Crime syndicates are putting in place targeted attacks, spyware and malware,” Quintana says.

Individual companies will have a hard time keeping up with solutions to these security problems, and will need help, he adds.


Return to main story