Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Data Security: Think Outside The Box
Newest First  |  Oldest First  |  Threaded View
Jeffrub1
50%
50%
Jeffrub1,
User Rank: Apprentice
4/29/2014 | 12:31:16 AM
Re: More about consolidation
As with many government initiatives, it could be further along than it is! I think we can all agree that data center consolidation is, point blank, a good idea (not just with cost cutting, but for environmental impact) and certainly a strategy that seems more private sector-esque (versus the usually more conservative, agency-specific IT policies of the government). The initial goals of the data center consolidation program were lofty: save $3 billion and shutter 40% of government data centers by 2015. It appears that won't happen. But I would say enough progress has been made to call it a modest success given the far-reaching goals.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/28/2014 | 3:51:53 PM
Re: More about consolidation
Thanks, Jeff. Another question: How far along is the federal government datacenter consolidation effort at this juncture? I've read several blogs and news articles, such as this one from Bob Otto, former CIO & CTO for the United States Postal Service. in InformationWeek, that the experience has been mixed? 
Jeffrub1
100%
0%
Jeffrub1,
User Rank: Apprentice
4/25/2014 | 1:21:10 PM
Re: More about consolidation
The prevailing security wisdom in the private sector - that all sensitive data should be kept within company-owned and operated data centers - is now changing along the lines of the federal government's data center consolidation initiative.  Specifically, it is often unnecessary and inefficient, particularly from an economies of scale perspective, to maintain separate physical data centers just to ensure data security.  Increasingly, companies are accepting cloud-managed applications and facilities to handle these once unthinkably risky data transactions.  The rationale goes beyond simple cost advantages; because these third parties are expert at data handling and security, they can actually improve the quality of the security.  Scale advantages include a deeper and broader experience with threat vectors and security breach possibilities, so security can be enhanced in ways that most smaller enterprises couldn't possibly be able to predict and react.
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
4/25/2014 | 11:02:59 AM
More about consolidation
Jeff, you make an interesting point about what the private sector can learn from the public sector with respect to consolidation of government datacenters. Can you give an example? 

 

 


News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: "Elon, I think our cover's been blown."
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-2296
PUBLISHED: 2021-04-22
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromi...
CVE-2021-2297
PUBLISHED: 2021-04-22
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromi...
CVE-2021-2298
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attac...
CVE-2021-2299
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful atta...
CVE-2021-2300
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of...