* Security considerations of management software
endif; ?>Most management systems today rely on agent technology that interacts with software on servers. So what would happen if malicious hackers targeted the agent or server software to gain access to the management system? Would they be able to do anything? See anything?
Management tools have a lot of capabilities to perform actions on all IT resources. Because of this, it is imperative that management systems provide adequate security within their systems to prevent malicious intruders from misusing the wealth of capabilities. Add automation to this equation, and if proper security is not in place, the IT infrastructure could be put at risk.
Enterprise Management Associates has seen a rise in management tools that specifically address security concerns by securing the communications between their agents and console software. In some cases, the transmissions are encrypted. In others, the sender of a request or of information (server or agent) is authenticated to ensure that the sender is legitimate.
Although it hasn’t been a problem so far, potentially security could increase with the adoption of automation. For example, when software components are allowed to automatically provision or de-provision systems, you want to ensure that the requests are legitimate and that they are authorized. In addition, as remote management is used increasingly, diligent security is imperative.
Another aspect worthy of due diligence is the integration of management products. It’s inevitable that management products must be integrated with one another. But how secure is the communication of data and information between two integrated products? Can the integrity of the management data be guaranteed? And can the source of the data be accurately identified? If effective security is not in place, could garbage data be sent to higher-level manager-of-manager tools, which may launch automated actions based on faulty information?
Beyond agent-server communication, a management system should also have security authorizations within the system, so that administrators can be granted authority only to the resources they are managing and so that they are only allowed to do specific management tasks to those resources. Many management systems have this capability today, where they allow distributed management task allocations – where administrator A has the authority to manage the systems in New York, and administrator B has the authority to manage the systems in San Francisco.
In some cases, some management tools use proprietary forms for communications between their components. Although these proprietary systems are frowned upon in the current environment of open systems, there is the advantage that malicious intruders may not be able to simulate the proprietary communications. As management systems become more open, the need for robust security of the management systems themselves becomes even more imperative.
Most management software uses password security. However, with the strength of the management capabilities of the tool, is password security enough? It may not be in certain cases.
So as you select management tools, add internal security of the management system to your list of requirements. The vendor must be able to satisfy your concerns about the internal security of the product.




