You can make your extended enterprise constituents take security as seriously as you do. Here’s how.
| |||||||||||||||||||||
Organizations planning to partner with Charleston Southern University in South Carolina better get ready for a rigorous vetting process. CIO Rusty Bruns is a stickler when it comes to security.
His biggest fear is that a hacker will find a security hole, break into university databases, and steal personal and financial information for thousands of students and alumni. “You have to make a conscious best effort that that’s not going to happen,” Bruns says. “I have to say we’ve done everything we can based on the school’s budget and the technology that’s out there to protect this information.”
Bruns comes by such confidence in part because he audits the CSU network every 12 to 18 months and subjects all prospective partners to a thorough third-party audit. (He has even budgeted for external audits, in case a potential partner cannot afford one.) Among the information he gathers are frequency of password updates, firewall-monitoring procedures, and found vulnerabilities or access holes.
Once he’s satisfied that the prospective partner has fixed any major flaws uncovered during the audit, he makes all project team members at that organization sign a security policy. With their signatures, they promise to take a variety of security precautions, such as changing passwords frequently, and they agree not to divulge any shared information. Bruns then checks the partner’s references, asking direct questions about how the organization handles security.
Even when Bruns is satisfied that a prospective partner can be trusted, he only extends the CSU network via direct links, using two levels of application-specific passwords and encrypting all transmissions. He could not achieve high enough levels of security if he allowed Web access, Bruns says.
The more the merrier
Vinnie Cottone, vice president of infrastructure services at financial services firm Eaton Vance in Boston, takes a different tack. He is a big proponent of partnering and doesn’t want to limit how many companies can access the network. To that end, he’s created the Business Partner Network.
The Business Partner Network extends to about 40 partners, including one outsourcer that operates Eaton Vance’s call center and another that cares for the firm’s client data records. Also linked to the Eaton Vance network are 250 companies that supply financial data feeds. Any participating company must sign a security policy, Cottone says.
“Everybody has their own infrastructure. Since we can’t mandate how it’s going to be in their networks, the onus is on our enterprise, not our partners. We’ve got to figure out how to do it,” Cottone says, especially given today’s proliferation of viruses and worms, and the increasingly stringent regulations.
Firms signing up to be part of the Business Partner Network can choose from a menu of connection options, Cottone says. “It’s more than a DMZ. We have Web-based applications, some private lines – it depends on the application we’re trying to push out,” he says. In the financial services world, “the big push is to go all Internet-based and get away from the real estate of private links,” he says.
Cottone employs an intrusion-detection and response system, and if he detects a problem with one of his links, he shuts down the port and moves the partner to a quarantined area to determine the cause. “It’s important to remove them from the production area,” he says.
Like Bruns, Cottone regularly audits the network.
Frequent audits of an extended enterprise should be a given but they’re often not, says Mark Townsend, technical marketing manager at Enterasys Networks. “I’ve seen contracts [our clients have] entered into where there’s no testing of the link at all,” he says.
|
Savvy IT executives will spot-check to make sure the partners they’ve drawn into their extended enterprises are cooperating with agreements, security experts say. Another smart move is going on-site at least once per year, experts agree.
For contracts that do spell out auditing procedures, the language on how to deal with security problems an audit detects must be clear, Townsend adds. “You have to decide what level of incident would cause a blocking of network access [until the fix is made] or termination of the agreement,” he says.
Before engaging the extended enterprise, IT executives should be well aware of architectural details. “You have to describe what service you’re going to provide, what infrastructure is going to be used to secure that service and what monitoring will be in place to check on the service,” Townsend says. “Are you going to use proxy servers? Will you open up Port 80 between the two networks? What access to what application will be needed? Who will be able to access that application?”
Partners must embed intelligence throughout the network to detect possible attacks, Townsend says. They must employ policy-based protection for all devices that will access the joint network. Installing access control lists and identity management tools are just two options for stemming unapproved traffic.
Get chatty
Partners also need to agree on types of encryption, anti-virus program for gateways and desktops, types of firewalls and which scanning engine to use. Even if it seems counterculture, security groups have to open up and talk.
“Security managers have a certain level of paranoia, and that’s not a bad thing. However, when dealing with business partners, they need to be open in discussing some of their security issues,” says Douglas Potts, security system engineer with CDW, a computer equipment retailer in Chicago. “It’s very important that before the relationship is formed, both security managers need to speak and collaborate.”
This might create tension, Potts admits. “One company might be calling the shots because they’re the bigger company, but that doesn’t mean that the smaller company doesn’t do anything,” he says.
Communication, of course, is critical when alarms happen. “There should be benchmarks for alarms on both sides outlined in the contract. If there’s a security breach on one side, there should be open and free-flowing communication. Everyone should be alerted,” he says.
Regulatory and compliance restrictions make this even more critical, Potts says. If you fall under government mandates such as Graham-Leach-Bliley, the Health Insurance Portability and Accountability Act or Sarbanes-Oxley, then you’re legally bound to make sure the data you’re sharing is protected – even if it’s off your network.
“If you’re dealing with a business partner who has not had experience with the new legislation, you must educate it,” he says. “If you join together, it’s your responsibility to live up to the standards.”
Gittlen is a freelance writer. She can be reached at sgittlen@charter.net .




