* Report from RSA on security management
At a time when several major IT events have fallen by the wayside, the annual RSA Conference continues to grow. According to conference organizers, this year’s un-audited attendance figure of 13,000 set an all-time record.
The reasons for RSA’s climbing attendance are clear: as security threats continue to mount and regulatory compliance commands a substantial portion of IT budgets, security and compliance continue to hold the attention of the market.
This continuing trend not only drives RSA attendance – it is also having an impact on how IT security and compliance spending is measured. We are well past the day when a reactionary security or compliance investment could be made as a knee-jerk reaction to emerging events. As spending continues, executives demand that security and compliance buying decisions stand up to the same rigorous evaluation as any other investment intended to deliver tangible returns or to decrease operating costs.
One of security’s many challenges has been to determine how best to make this evaluation, when performance metrics may not be apply (in security’s case, when nothing happens, it’s a good thing!). The answer is found in risk management methodologies, which are increasingly called upon to provide decision support for security spending. As a result, vendors are positioning products on the basis of their risk mitigation value. Accordingly, “risk management” served as one of this year’s recurring RSA themes – as it increasingly does throughout the security and compliance market.
One other major theme of RSA 2005 was the increasing visibility of the integrated systems approach to security and compliance. Arguably the most compelling keynote was that of Cisco CEO John Chambers, who presented Cisco’s most systematic approach to security management yet. Though Cisco has many worthy competitors in security, the company captured significant mindshare at the conference by unveiling a comprehensive set of new or updated products embracing many key aspects of network security.
The systems theme was not confined to Cisco, however. Sourcefire, the IDS innovator, was recognized for its integration of aspects of intrusion detection and prevention, network topology awareness, behavioral anomalies, and management. Competing for this recognition were other innovators such as Skybox Security, whose central value in vulnerability management is awareness of network context as a whole.
Two major drivers seem to be motivating the trend toward systematic security implementation. One is the increasingly complex nature of threats. Multi-functional worms can locate targets as well as propagate themselves. Attackers are able to discover and exploit entire networks of hosts that they can convert into large-scale attack platforms, often in silence. As threats continue to change, the dynamic nature of security requires systematic vigilance across the enterprise.
The other driver is IT consolidation and convergence. Though the economy may be improving, IT managers are anxious to preserve the efficiencies gained through the lean early years of this decade. As a result, the consolidation of available platforms joins with the convergence of all kinds of content in IP networks as leading motivators of this trend.
Executives also seek to simplify their environments as well as the number of vendors they do business with. This is good news for companies such as F5 Networks. F5 converges SSL performance and security with application delivery on unified platforms. Not surprisingly, the F5 booth was noticeably jammed with traffic throughout the show.
These factors add up to the continued health of the RSA conference and the market it represents, despite the economic influences that continue to weigh on other aspects of IT. Key aspects of management are still required, however, to bring the cornucopia of innovation represented at RSA into a manageable whole, such as enterprise-wide policy management and identity-driven technologies. We’ll take up these topics in newsletters to come.




