Security automation: A new data center mandate
Everyone says they want to automate security functions, but few have done so fully. This is true even of the most mature security automation functions, such as intrusion detection, patch management and virus protection. Alerts are automated, but more often than not, responses aren’t. The results of a recent security survey conducted for Network World by AFCOM, an association of enterprise data center managers, certainly bear this out.
In that survey, 99% of 157 total respondents identified the need to automate security functions as a “moderately important” or “critical” corporate strategic value. But only 14% of respondents said they automate responses for most types of alerts. The largest percentage – 44% of the respondents – reported handling all security alerts manually, with another 42% automating responses to only a few types of alerts. What’s more, when it comes to managing security information, the largest percentage – 36% – rely on vendor point products rather than an integrated management platform.
However, progress is being made on the security integration front, as 28% report that they do integrate into a systems manager; 22% integrate into a security manager (14% indicated they do something other than run vendor point products or integrate into either a systems or security management platform).
Enterprise security won’t ever be 100% automated – trust and cost are two factors prohibiting full automation. But security must become automated substantially enough as to become part of normal business operations.
Bringing that about means making security automation a core new data center component. Security functionality must be embedded in the network layer, for example, and companies must be willing to build security operations centers (SOC). Similar in concept to a network operations center, an enterprise SOC continuously monitors and manages a range of security devices and events to maintain and ensure overall network security.
This supplement explores these and other best practices for getting security to a more automated state. I hope we’ll soon see less of a disconnect between the security automation ideal and today’s reality.
– Beth Schultz, bschultz@nww.com




