Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

So Long, Security Silos

RSA prez Art Coviello underscores security's closer integration with IT infrastructure

Feb 06, 2007 | 04:10 AM

By Terry Sweeney
DarkReading

SAN FRANCISCO -- RSA Conference -- Data growth, its increasing value to the enterprise, and the resourcefulness of cybercriminals underscore the importance of multi-layer security for enterprises, and the equally large parallel requirement of security simplification, the president of RSA said this morning in his opening keynote here.

"Security has traditionally been about imposing limitations, rather than lifting them. It's time to force that to change," said Art Coviello, president of EMC's RSA security division. Threats and challenges should not be the only motivation -- opportunities like accelerating new ways of doing business must also factor highly into the mix.

He went on to challenge the audience to think about security, not just in terms of firewalls and antivirus software, but also fungible assets, the customer experience, internal assets, and brand integrity. "Security impacts all that and we must treat security within that broader context," he said. "Information security has become a complete misnomer -- we've protected the perimeter but not the information itself. Despite digital rights management (DRM), we haven't linked security to DRM. And information has this nasty habit of wanting to move around.

"Security can no longer exist in silos in our companies or in the industry, or as a tactical afterthought," Coviello added. "It's no longer enough to build an outside-in approach -- we must simultaneously master an inside-out approach mapped to security -- an info-centric approach."

The fact that this new business model just happens to map to EMC's reasons for acquiring RSA wasn't lost on the audience, or an interviewer who posed questions to Coviello and his boss, Joe Tucci, EMC's chairman, who later joined Coviello on stage. With EMC (and Cisco, IBM, Microsoft, Oracle, and others) trying to be enterprises' one-stop infrastructure management stop, will discounts for volume or loyalty be forthcoming?

Tucci sidestepped the issue but offered up this politic response: "We'll make sure we drive down costs for customers and that they get better prices across the board. I guarantee it."

In that same vein, Coviello said vendors didn't understand the complexity they were introducing to customer networks, particularly where security's concerned. And he claimed vendor combos like EMC-RSA can actually simplify security and management.

"To have security tightly woven in makes more sense for everyone," Coviello said, adding that RSA was launching a risk assessment consultancy via EMC's professional services organization.

— Terry Sweeney, Editor in Chief, Dark Reading

  • Cisco Systems Inc. (Nasdaq: CSCO)
  • EMC Corp. (NYSE: EMC)
  • IBM Corp. (NYSE: IBM)
  • Microsoft Corp. (Nasdaq: MSFT)
  • Oracle Corp. (Nasdaq: ORCL)
  • RSA Security Inc. (Nasdaq: EMC)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)