After a few week hiatus from the security front, we’re back on the trail of finishing out the 10 part “Securing the Line” series. Today, we’re focusing on host security, or securing the underlying system that supports convergence applications. Platforms that exist on top of non-proprietary OSes are great things. They allow for ease-of-management, and easier integration into other systems. However, what happens when critical security updates are released for the host OS, only to be unsupported, or worse, unrecommended by the application-level vendor? This is a problem that reaches far beyond the Convergence / VoIP fields. Many early manifestations of this very problem evolved in the medical and healthcare fields, where an unsupported patch or fix could put someone’s life in danger. Thank goodness that ‘most’ implementations of UC or VoIP systems won’t put lives in danger, but it’s still possible. However, this type of issue can put your systems and data at risk. So, you may ask, how is this problem easily solved? First of all, you as the “consumer” do have the potential to positively impact the situation from several fronts. First, if you are in the RFP process for any UC or IP-PBX, develop a list of security questions and requirements. Make sure to include questions about turn-around-time support for critical security vulnerabilities introduced into the host system. Secondly, remember that the companies that develop communications systems ultimately work for you, the customer. It is possible to voice your concerns about these problems to your VAR, support contact, or through other channels. There is good news! These problems are slowly diminishing, and have been for the last few years. More VoIP and UC systems companies use a host OS on which they run their system. Eventually, better patch management strategies have been implemented, and the turn-around is significantly shorter in length.
Securing the Line Part 8 – Host Security Considerations
Opinion
Oct 17, 20082 mins




