About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
Security Advisor
P.J. Connolly

U.S.-China incident inspires another look at the importance of effective IT security

YES, MY VACATION was wonderful, thank you very much. When the first Monday morning back on the job rolled around, I had only two regrets: that I hadn't taken a longer vacation and that I had 6 jillion e-mails to wade through. Fortunately, 80 percent of them went into the "later" folder, and most of the rest were invitations to the recent RSA Security conference in San Francisco. That left me with a handful of messages that either had obvious importance or looked too interesting to ignore for long. I admit that I have a dogged curiosity -- between that and my big mouth, I can get into a lot of trouble if I'm careless. But that curiosity is also what makes me good at my job; so if someone or something catches my attention, I usually let myself be diverted.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
That morning, the eye candy was a subject line linking the American Aries II ELINT (for electronic intelligence) plane that was forced down on Hainan Island at the beginning of April to a conspiracy to transfer restricted technology to China. Given that the incident was a topic of conversation even where I'd been vacationing and that I love a good conspiracy theory, how could I resist opening the message? Besides, there weren't any attachments to deal with, and I wasn't about to click on any hyperlinks because I had a lot to do that morning.

The message turned out to be a plug for Troika Magazine, which referred to the whole business as a "black op" -- an intelligence operation of which a government will deny knowledge -- and basically appealed to the same mentality that causes people to watch the skies for black helicopters.

Security arms race?

I generally don't spend a lot of time thinking about "what-ifs" -- the history we know is already sordid enough -- but the pitch closed by pointing out the possibility of an arms race in the security field as a by-product of the Aries II incident. This might not be such a bad thing, of course. Let's face it; we could use a sense of urgency in this area. After all, even in the current economic climate, security is one area where IT departments have legitimate reasons for increased spending. I can't go more than a day or two without hearing of yet another brand-name company being hit with Web site defacement, DoS (denial of service) attacks, or database theft.

Because the current condition of corporate IT security is intolerable, I'm willing to consider any event that focuses attention on information security as a blessing. If the crew of the Aries II was able to disable the plane's classified equipment -- and press reports indicate this is so -- the Chinese military may simply have got their hands on some very expensive paperweights. On the other hand, if the claims made in the Troika article have any truth, I expect that the U.S. military and the National Security Agency have already thrown out their plans for the next generation of intelligence-gathering Tinkertoys and are looking at some radical alternatives.

But I really don't believe that the incident was anything more than a case of a hotdog fighter jock who decided to take matters into his own hands. After all, there are a number of easier ways to transfer technology that don't involve putting two dozen lives at risk. Because the real goodies on the Aries II were the software and the collected data, the whole thing could have been done via the Internet.

Nevertheless, the point about a security arms race is valid. Make no mistake about it: The global economy depends on IT security. If security measures don't evolve to meet ever-changing threats, the prospects for the future look bleak. Unfortunately, many companies don't get really serious about security until they get burned.

Remember, I'm not talking about physical security; we know how to do that very well. Some companies have elaborate physical security arrangements that would make the CIA proud. But now that it's open season on corporate and government systems, I'd argue that most physical access controls are a waste of time and money. The money would be better spent on building up a company's IT security effort. In most cases, a simple lock on the door will suffice to cover your physical security needs.

But if you think that installing a firewall, some anti-virus software, and a VPN means you're secure, then you've missed the point. You don't get security from installing products; you become secure by implementing secure processes.

Most companies still haven't fully grasped that concept, and they'll continue to be vulnerable to computer attacks. I really worry about the thousands of midsize and small businesses that are lucky to retain one or two system administrators. They're extremely vulnerable to attack because their staff have their hands full explaining to users that no, this isn't a cup holder.

If we do find ourselves in a security race soon, my hope is that vendors will start designing systems in which security is integrated, instead of bolted on as an afterthought. But I'm not that optimistic about the future.

Get Security Watch free via e-mail

To get my column for free each week, sign up at www.iwsubscribe.com/newsletters.


Test Center Senior Analyst P.J. Connolly (pj_connolly@infoworld.com) now knows he should have taken another week of vacation.




RELATED SUBJECTS

Security

MORE >


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no