Symantec showcases the ‘Security of Information’

Opinion
May 25, 20064 mins

* Securing data is a vital aspect of enterprise risk management

Editor’s note: While Mike enjoys some time off, his colleague Scott Crawford fills in.

For many years, the security of business-critical information was considered a function of securing the enterprise against threats which were seen primarily as external. Establish a secure perimeter, defend against viruses and attacks from outsiders, and all would be well within the organization. No need to apply specific security measures to data in storage – at rest, in use or in transit – since that’s the point, after all, of establishing an internal trusted network. Right?

Wrong. So says not only a flurry of regulation that in the last few years has come to dominate a significant aspect of IT spending, but also the risks to which sensitive information is exposed today. According to the Privacy Rights Clearinghouse, there have been over 160 data security and privacy breaches in the last 15 months. Sensitive business data and intellectual property are at risk along with personal information. Today, securing data itself is no longer considered extraordinary. For many organizations, it has become a vital aspect of enterprise risk management.

Here at Enterprise Management Associates, we are currently at work on a landscape study entitled “The Security of Information,” which will examine the many segments of the market growing up around the multiple risks and issues faced in meeting this now-critical requirement that, at long last, brings the security of storage to the fore – and much more. It was therefore fortuitous timing that I had a chance to take a look at some of Symantec’s approaches to this challenge, at the company’s recent “Vision” conference in San Francisco.

Symantec’s message management strategy demonstrates the evolution of the company since the Veritas merger, as well as some of the key issues that a data security strategy must address. In his Vision keynote, Jeremy Burton, Senior Vice President of Symantec’s Data Management Group, painted a highly compelling picture of just how multifaceted a message management strategy must be, and how central security and compliance are to that strategy. He offered some very provocative data points to illustrate the business-critical nature of messaging, such as his contention that a company with 100,000 employees generating less than 40 e-mails a day could create over 4 billion messages in 3 years. To give you an idea of scale: in early 2004, that was the size of Google’s entire site index. Yet many regulatory mandates require the maintenance of some information for several years, such as the record of disclosure of personal information, no matter how transmitted.

Burton’s bullet-point priorities for message management include: keeping system costs down, keeping bad things out, keeping important things in, keeping things only as needed, finding important data as needed, and mining it for business-relevant information.

Symantec’s security assets as well as its Brightmail acquisition have given it a strong platform from which to enforce the keeping of bad things out – but what many may not be as familiar with are the tools Symantec’s message management products can do to keep important things in, such as personally identifiable information. Protections against outbound risks are increasingly becoming central to message management, to which Symantec recently added its acquisition of IMLogic, for applying security and compliance policies on instant messaging – inbound and outbound – as well. Search capabilities that correlate business-relevant data from a mass of unstructured messages complement the Symantec approach, providing means to demonstrate regulatory requirements in audit as well as forensic analysis of potential security events that could threaten the integrity and proper use of business-critical information.

These are just a few of the issues raised by today’s focus on the security of information. Expect more to come – from Symantec and other vendors, as well as from us here at EMA on this highly important topic very soon.