Implementing security without sacrificing business agility

Opinion
Feb 8, 20053 mins

* Tips for building an infrastructure that is flexible and secure

In the next-generation data center, the utility computing model provides tremendous business agility. If you build your data center on a utility model, it allows you to deploy applications rapidly to meet business goals. If you have a period of unexpected demand, your data center could automatically provision more servers or relocate applications to faster systems. In this environment each server is generic, each application is portable and the data center resources are all virtualized.

But what about security? How do today’s security products fit in such an environment?

For many IT executives attempting to implement a utility computing environment, security is not an easy fit. Most security products are implemented as vertical “silos.” Often implemented as appliances, these security tools (firewalls, IDS/IPS, anti-virus measures, etc.) are usually strategically located at choke points on the perimeter of your network. They are in static positions, protecting a set of static servers, which are located in static trust domains. Not very flexible, indeed.

While the traditional security model of the “perimeter bastion” was effective in the past it is increasingly less effective. The perimeter itself is porous, so there are more trust relationships with external networks. The internal network itself is vulnerable to fast-propagating malware, which can jump from server to server. As a result, IT executives are trying to develop new strategies to manage risk. These strategies should be synchronized with the data center strategy for agility, if they are to succeed. The danger of having a static security infrastructure while building a dynamic data center is not that the security will be ineffective – it is that the agility of the dynamic data center will be lost.

Here are some of the considerations for building a next-generation dynamic security infrastructure:

* Deploying security on each critical system provides far more granular control than front-end chokepoints.

* You can’t move an appliance, but you can re-deploy software.

* Software-based security can be provisioned automatically, at the same time as the applications on each server.

* Flexible security products should support dynamic trust “zones,” which can automatically compensate for applications being moved around the data center.

* IP address-based access control is not only weak – it is also extremely inflexible. Avoid network-layer security based on IP address.

Each time you put a security device in your network, you create an artificial bottleneck and a hard line separating your infrastructure. While this model has worked for many years, it will be increasingly difficult to reconcile with your dynamic data center. Sacrificing business agility in this manner may be a lot riskier for the business as a whole than a security breach.