* Security report from the RSA Conference
I’m writing this article from the RSA Conference, so here are some of my impressions and observations of what’s happening in security and of the conference itself.
Keep in mind that these observations come from my network/systems management (NSM) and application management orientation, not from a pure security-fanatic view.
One thing is clear: There are and have been changes afoot in the security arena. As vendors look to broaden their offerings, build more fully functioned suites, or fill in holes in their product offerings, acquisitions or “strategic” partnerships seem to be the order of the day.
One area in particular that has resulted in successive acquisitions of players is identity management. Examples of some of the players that have been acquired in recent years and months are: Access 360 by IBM, Business Layers by Netegrity, Select Access by HP, Waveset by Sun, and the list goes on. Vendors who have acquired identity management capabilities see it as a strategic foundation of more fully functioned suites, and are using these technologies to prepare future security capabilities for Web services or service-oriented architectures.
Integration continues as a trend, and not only between security products. We’re also starting to see more evidence of security management being pulled out of its organizational silo and moving more into the mainstream with other NSM and application management products.
In my view – and here is where my NSM bias shows – security must become an integral component that interacts and integrates with NSM and application management tools to better protect IT resources and assets and the business as a whole.
Security product interoperability and integration is helping IT organizations pull together the compendium of security point products that they are using in their enterprises. However, the vendors and their offerings on the conference exhibition floor are evidence that many of the current security management tools address very specific aspects of security. This is still true of many of the “suites” – they solve some of the security issues, and they are not comprehensive security products. Although there are integration efforts completed and under way, this is still a work in progress. But it is clear that security management is changing and maturing.
To truly take advantage of many of the leading-edge security technologies in a short period of time, IT organizations must come to the table with security discipline, policies, procedures and methodologies already in place. Security technologies will not be a panacea for chaos – if you’re in a state of chaos, you’ll still have to work through the task of putting in place security discipline before you can leverage the new technologies. You’re sure to fail or receive reduced benefit from the new deployment.
One thing that was certainly evident at the RSA Conference is the fact that there are so many aspects of security, and a multitude of vendors and products. Even if you came to the conference with a huge security management budget, it’s clear that your huge budget would be exhausted well before your security needs and wants are satisfied. There are tools like firewalls, specialized security appliances, security forensic tools that help to analyze risks, vulnerability tools, intrusion detection tools, authentication tools, authorization tools, encryption tools, tools that analyze network traffic to identify potential security threats, tools that analyze user behavior to identify potential security threats, wireless security tools, anti-spam, anti-virus, RFID, Web services security, single sign on, regulatory compliance tools and more.
So many tools, so little time and budget.




