In 2007, IT executives will need to clearly evaluate risk as they weigh sometimes opposing proposals to bolster security, increase wireless connectivity, extend more business processes over the Internet and address regulatory requirements.
If that’s not enough, some say the adoption of VoIP technology, which is subject to denial-of-service and stolen capacity, may lead to disruptions in traditional circuit-switched telephony as well.
“More trouble is yet to come in VoIP, and hackers are going to gain complete control over your VoIP network,” says Rohit Dhamankar, senior security manager at 3Com.
|
Because VoIP servers “are interfacing with traditional ‘old phone’ networks,” he points out, hackers are likely to launch attacks through VoIP that will seriously affect the telecom infrastructure, such as Signaling System 7 for call setup. The result: downtime and criminal exploitation of the circuit-switched phone system through VoIP.
Other trends, says Friedrichs, can be traced to Web 2.0 technologies, such as AJAX, which support very flexible access to server resources behind the corporate firewall. This very flexibility appears likely to facilitate a new genre of exploits that will be difficult to detect and analyze, he notes.
Meanwhile, with Microsoft’s Vista was expected to begin to gain a footprint in the enterprise and on consumer desktops in 2007, all eyes will be watching how well it holds up without patching. So far, some are at least optimistic. “Microsoft has made significant improvements in the core operating system,” Friedrichs says.
Wireless demands
While it may be tempting to batten down corporate systems as these new threats emerge, IT departments in 2007 will find it nearly impossible to ignore the scads of employees, business partners and customers clamoring for greater mobility and wireless access to systems.
“For most enterprises, CIOs see mobility as absolutely essential,” says Stan Schatt, vice president with ABI Research. “They are getting so much pressure from their internal customers for this. IT is being forced to acquiesce” in the mobility quest.
Fortunately, as user demands escalate, wireless networks — both wireless WLANs and cellular data networks — are poised to get a lot more effective in the coming year.
Draft 2 of the IEEE WLAN standard is expected to become final in February or March, and the Wi-Fi Alliance is expected to launch its certification testing for draft 2 products by about May. Products based on the draft standard are expected to start appearing by midyear and could have a major impact on enterprise backbone networks. These products, with throughput of 100M to 300Mbps, will be aimed first at the residential, home office and small-business markets, which already have been snapping up so-called pre-11n gear that began shipping in 2006.
The year ahead Here’s a collection of key industry events happening or expected to take place in 2007. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Because 802.11n won’t be formally approved until early 2008, it’s unlikely that companies will adopt these prestandard products. But they will be evaluating them and their possible impact on the existing wired infrastructure. “The effective data rate from an .11n access point could be well over 100Mbps,” says Craig Mathias, principle with Farpoint Group, a wireless consultancy. “It will swamp [some] existing switches. Gigabit Ethernet is something you sort of need to have [for .11n].”
Additional 802.11 standards coming in 2007 will make enterprise WLANs more consistent, more manageable and better performing, says Paul DeBeasi, a Burton Group senior analyst. In the third quarter, the completion of the standard will create a standard method for very fast roaming between access points, seen as critical for good wireless VoIP calls.
The standard for radio resource management specifies what management data can be collected from WLAN clients, not just access points. This will be combined with the 11v standard, which will give the WLAN infrastructure greater control over client devices, creating a more predictable, consistent WLAN.
Meanwhile, cellular data services will continue to improve dramatically in 2007. Subscribers will see two-way throughput in the 400K-to-700Kbps range, and much lower latency, based on standards such as Revision A and HSDPA/HSUPA. Carriers are aggressively expanding the footprint for such services, making pervasive mobile computing more feasible than ever.
With both WLANs and cellular data networks more capable, expect to see an explosion in so-called dual-mode smart phones, which can operate on either network.
Finally, increased mobility will highlight new security problems — not in the wireless networks but in the client devices that use them. The spread of mobility in 2007 will force enterprises to be more systematic about securing client devices, protecting the corporate data on them, and protecting the corporate networks they access.
Compliance quagmire
Just as there will be no letup from security threats in 2007, users won’t find much relief from regulatory requirements either.
Laws in effect this year portend more of the same: They expand requirements to retain e-mail and other documents and encrypt confidential consumer data being stored. New rules on the evidentiary discovery of clients’ electronically stored information, international banking rules and more detailed interpretations of the Health Insurance Portability and Accounting Act will spur customers to put mechanisms in place to more quickly discover and retrieve archived data.
Changes to laws protecting the privacy of customer’s confidential information also are on tap for 2007. Following California’s lead, about 30 states have imposed rules that require organizations to disclose when data leaks have occurred. A ruling under consideration in the federal government right now – the Notification of Risk to Personal Data Act – requires federal agencies and companies engaged in interstate commerce and in possession of data containing personal information to disclose any unauthorized breach or loss of such information.
In the financial services and banking industries, two international laws will affect how organizations retain, recover and report on data. BASEL II, which took effect Jan. 1, requires the worldwide banking community to uniformly capture data to allow operational risk factors to be identified and analyzed. The Markets in Financial Instruments Directive, which requires compliance by next Nov. 1, is the European Union’s rule that sets out basic high-level provisions governing how business should be conducted.
Compliance with these rules will be a tricky matter for multinational companies, because they can differ from rules imposed in the United States. “Privacy policies in Europe and discovery policies in the U.S. are very different,” says Francis Lambert, senior compliance adviser to Zantaz, an e-mail and archiving vendor. “There is no international body that is going to solve this for [companies].”
The compliance quagmire also may change depending on how the incoming Democratic Congress views it. “In the past several years there has not been a focus on enforcement,” Lambert says. But enforcement could increase with the Democratic Congress, he suggests.
NAC matures
While lawmakers are busy detailing rules about how data should be stored, technology vendors are equally busy devising ways to protect enterprise resources from harm while complying with all the government rules. One technology that will continue to generate buzz in 2007 is network access control (NAC).
This year NAC is going to become more mature, and some long-talked-about contributions to the technology finally will be available.
The three major spheres of influence within the NAC universe — Cisco, Microsoft and Trusted Computing Group (TCG) — each envision a method of checking whether devices that are trying to access networks hold a security posture that is in line with policies set by the corporation. If not, the NAC system will deny that device access or limit it to a quarantined area of the network.
These big names in NAC will reach milestones this year. For example, sometime after June, Microsoft says it will release its Longhorn server, which is an essential component of its NAC scheme known as Network Access Protection (NAP).
In addition, Microsoft Vista, which is being released to consumers in January, includes client software necessary to support NAC. This is key to some other vendors, including Cisco, whose NAC architectures are receptive to Vista’s NAC support, because it means customers won’t have to add one more thing to their desktops and laptops if they want to deploy NAC. Similarly, the release of Longhorn in the second half of 2007 is important to Cisco, because it will include the Microsoft NAP agent.
For its part, TCG is publishing standards for NAC components that will lead toward vendor interoperability.
The IETF also has jumped into the game, establishing a working group to develop NAC standards. That effort is behind the curve, because the group was just set up in November and won’t meet again until March. But every step it takes will be significant in that key vendors participate in the group and typically implement technology based on the best current working version of developing standards.
Outside the three main NAC camps, smaller vendors will make headway among budget-conscious customers in 2007, industry watchers predict. Vendors such as ConSentry, Nevis and Vernier make appliances and switches that can enforce policies and keep a lookout for misbehaving machines. Customers who are in need of NAC but don’t want to invest yet in networkwide upgrades will increasingly buy these devices in 2007, says Zeus Kerravala, a Yankee Group analyst.
Enterprises also will consider buying NAC software and appliances from the likes of McAfee and Symantec, whose dominance in client-protection software provides a foundation for determining the security posture of endpoints.
WAN assistance
Another hot technology in 2007 will be optimization and application acceleration. This year the key players are all about equal rights for users.
Emerging software-based tools will enable mobile and teleworkers to get all the benefits of acceleration appliances that users in headquarters and branch offices do. The technology, dubbed soft WAN optimization controllers by research firm Gartner, must be intelligent enough to handle mobile users that may be accessing the network from various locations.
“This technology needs the same sort of functions that are in branch appliances, but it needs to run in a Windows environment, so the programming model is very different,” says Joe Skorupa, research vice president covering networking and communications equipment at Gartner. “It also has to be smart enough to know when people are in the office or plugged in from a remote location without an appliance nearby.”
Application-acceleration technology, WAN optimization’s data center cousin, will experience some fine-tuning of another sort in 2007. Application-acceleration tools reside in the data center and boost user performance of browser-based applications by offering several technologies, such as TCP optimization, that work at the network and applications layers.
According to industry watchers, 2007 will be a year in which the network becomes much more application-fluent. Because use-case scenarios for poorly performing applications vary among enterprise IT shops, vendors in 2007 will start making it clear which applications their technologies address, Yankee Group’s Kerravala says. “Vendors in this market have to get better about articulating the value of their product to specific applications,” he says.
Virtual apps and machines
Just as employees are becoming more distributed, so too are IT environments. Two separate trends on the application side of the house are adding to the complexity.
The first is the growing acceptance of software delivered over the Internet. Once a consideration for small enterprises with limited IT budgets, more large enterprises with complex application environments are buying into the idea of software-as-a-service. Gartner predicts 25% of new business software will be delivered as software-as-a-service by 2011, up from 5% in 2005.
Meanwhile, IT departments are orchestrating an architectural overhaul in-house that’s changing the way applications are designed and deployed. The rush to service-oriented architecture () will accelerate in 2007 as enterprises move from piloting Web services and other services-based components to production mode. Gartner predicts SOA will be used in part in more than 50% of new, mission-critical applications and business processes designed in 2007, and in more than 80% by 2010.
To help get a handle on increasingly distributed resources, industry watchers expect to see network and system-management market vendors tailor their wares to tackle virtual machines, maintain hardware and software configurations, and streamline automated workflows.
For instance, the rise in virtual machines will emphasize the need to manage the various platforms — Xen, VMware, Microsoft and others — across distributed networks. IDC predicts that 72% of all servers will be virtual by 2013, and Stephen Elliot, a senior analyst with the research firm, says that has management vendors scrambling to ship in 2007 products with virtual management capabilities.
“As Microsoft gets more product out and as the virtual realm becomes more heterogeneous, management of virtual infrastructure is going to get much, much hotter in 2007,” Elliot says.
Vendors that can automate the creation, distribution and management of virtual resources, which will converge with SOA’s loosely coupled elements, will come ahead of the pack, says George Hamilton, director of Yankee Group’s Enabling Technologies Enterprise group. “And along with that comes more automation and configuration technologies, especially in the area of IP telephony.”
Enterprise IT managers will need in 2007 an integrated system that can tap configurations across software and hardware IT assets, adds Dennis Drogseth, a vice president with research firm Enterprise Management Associates.
“IT managers need a policy-based means to access all this configuration information to enable higher-level management of performance across network, server and applications,” Drogseth says. “The number one question asked when diagnosing a performance issue among enterprise IT managers is, ‘What changed?’ and with quick access to that data, IT manages can fix problems more quickly.”
With solid configuration data, network managers can put in place technologies that would enable day-to-day tasks to be completed by software rather than manually by IT staff. While automation is hardly new, the move toward automating day-to-day tasks is also coupled with adoption of process-based management, says Jean-Pierre Garbani, a vice president with Forrester Research.
“In management, customers are thinking a lot about process and less about technology. They want the technology to help enable their processes,” Garbani explains. “Process automation will be big in 2007, and it’s new in the sense that data will be exchanged by integrated systems rather than one person passing it on, and more sophisticated tasks will be launched by software.”
Last, in 2007, network managers are expected to at least consider open source management applications. While open source options won’t have an immediate impact on vendors such as BMC, CA, HP and IBM, they might inspire these bigger players to add more interoperability and open formats to their proprietary software platforms, industry watchers speculate.
“There is a lot of investment happening around open source management, and while it’s still on the low end, people like the price point and the flexibility open source management offers,” says IDC’s Elliot.
Open source smackdown in 2007
Help from outside
As IT departments work to provide better services to users, many won’t go at it alone.
Greater numbers will turn to managed service providers, industry watchers say. In particular, remote management and monitoring, hosted VoIP, and IP audio and videoconferencing services will catch on.
“Eighty percent of enterprise customers have expressed interest in remote monitoring services,” says David Willis, a research vice president at Gartner. Customers want a service provider to monitor their network and detect sources of failure while still being in control of the assets on-site.
Likewise, more users in 2007 are expected to adopt hosted VoIP services, says Lisa Pierce, a vice president at Forrester Research. Although hosted VoIP services are a small part of the overall managed services market today, Pierce says capital restraints will drive more users to this alternative, which takes the worry of keeping up with new code and patches out of the customer’s hands and puts it in the carrier’s hands.
“The happiest customers I’ve ever met are customers that are using hosted VoIP services,” Pierce says. “Some companies just don’t have the resources to do VoIP in-house. The gear is different ages and from different vendors, and they can’t afford the capital expense to change all of it out. By going with hosted VoIP, users can dodge a bullet.”
More customers also are expected to buy managed IP audio conferencing and IP videoconferencing services rather than try to support these applications internally, says John Burke, a principal researcher at Nemertes Research. “Based on preliminary research results, real-time collaboration will drive the needs for these services,” he says.




