Security is hard work

Implementing effective IT security involves long hours of planning, monitoring and analysis

Written by Neil Barrett

Over the next few weeks, I have the exciting opportunity to build a small, hopefully secure computer network from scratch - complete with web server, email and office servers; an air-gapped collection of particularly secure systems, and an office network of laptops and desktops. And, in what I suspect will be seen as a brave step, I have to make at least a part of the network Wi-Fi to get around a problematic aspect of the building in which the network will be established.

I have to admit, for a long time I was less than confident about implementing a wireless network, due to concerns about "war-driving" hackers and the like. But in fairness, the convenience has convinced me the system is worthwhile.

Of course, the network will have a firewall and a reasonably sensitive intrusion-detection system; and of course, the most important of the servers will be free-standing - the old "sneaker firewall" being one of the best forms of defence.
I'll implement strong authentication on the router itself, and some kind of encrypted protocol over that. And perhaps more importantly, I plan to have a single monitoring station to record and illustrate the allocation of network addresses by the router, so I can spot if anyone manages to sneak a connection. Maybe I'll implement a frequently-changed password for the Wi-Fi connection, or maybe I'll put my trust in the existing authentication mechanism.

Time and close monitoring will show me which is best - particularly if I stick to my current thought, which is to turn the wireless router off at the end of each working day.

With care and a little forethought, secure networks can be implemented - though only, in fairness, at the expense of a little convenience. But that is the most important observation: security is at the expense of other things.

Too many organisations implement secure environments, or plan their information security, without considering the issues of expense and general risk analysis. Risk analysis involves working out the cost of losing the data - loss of confidentiality, integrity or availability - and the likelihood of different types of threat emerging. It involves calculating the cost of the security measures, and then the extent to which those measures do indeed protect the information assets from the different types of threat. And then it involves spending money and monitoring the results.
The data will be protected in as many different ways as I can imagine and can afford. I plan to do everything that I can possibly do to protect it... and then I need to plan for what I will do if anything goes wrong.

Security involves planning for all eventualities one can imagine. But I need to think of everything; and an intruder only has to find one chink in my technical and organisational armour. Remember, security is something you do, not something you have done.

Have your say, here:

Tags:

reader comments

related articles

 

London retains Wi-Fi crown

City outpaces New York and Paris in wireless survey but has poor record for security 29 Oct 2008

The main internet threats for 2008

Mobile malware, botnets, phishing and ID theft 24 Dec 2007

Healthcare workers putting patient data at risk

Personal mobile devices used to store confidential information 20 Nov 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation