Enterprise Network Management - True Defense In Depth

Managed security services from traditional carriers,across the networks of the hundreds of carriers and
Managed Security Service Providers (MSSPs), andproviders with which they have relationships. Due to
other solutions have helped address some of the costeconomies of scale, these VNOs are able to employ
and resources issues inherent within a Do-It-Yourselfthe best-in-class technology and expertise that might
(DIY) approach. But many enterprises are beginning tobe difficult for a single enterprise to afford. And the
realize they need more. In a typical environment,enterprise receives a tailor-made network and security
individual security devices report independently to asolution; VNOs work closely with their customers on
central site without a mechanism to correlatenetwork design and deployment, since the proper
information from all sites or to identify and addressplacement of security devices within the network is
network-wide events in real time.critical to success.
The complexity of today's global networks requires aDetermining the Level of Risk
managed security solution that addresses multipleEnterprises cannot apply the appropriate level of
dimensions within the network to provide defensesecurity to their networks if they are unaware of their
against risks ranging from spam, email-borne viruses,risk-and the level varies depending on the enterprise.
and spyware to loss of confidential information andCustomers can determine risk by performing a risk
intellectual property. Such defense in depth solutionsanalysis, either directly or through an external
must be multidimensional to apply security acrossassessment. An analysis will assign value to resources
multiple layers of a network-within the customers'based on multiple criteria, such as the number of
premises, in and across the backbone, and extendingapplications on a resource, the frequency of use, and
to each remote and corporate partners' office.the potential impact of downtime. Systems that serve
Security, in other words, is provided to all parts of themultiple applications to thousands of users will likely
network, wherever connectivity is extended.have a significant impact if unavailable and therefore
Many still consider security as protection againstrepresent considerable risk if unprotected.
Internet threats; a multidimensional approach, however,Risk analysis includes an assessment of the current
recognizes there are many different untrustednetwork design, including the number of resources
networks and that enterprises do not necessarilyavailable to different customers. It also recommends
know what all employees are doing or where they arewhere security devices such as firewalls and IPSes
taking their resources. The multidimensional approachshould be placed or added for protection. The analysis
looks at all connectivity and protects any method ofcan also take federal, state, and industry regulations
access through any channel, even down to theinto consideration. For example, an analysis can note
individual user.where applications subject to Sarbanes-Oxley (SOX)
Layers of Protection for Defense in Depthcompliance are located and inform the enterprise if it
Effective multidimensional solutions include severalneeds to add risk prevention aligned with SOX
layers of protection to enable the appropriate defenserequirements. Good assessments arm an enterprise
in depth for various network resources. Small remotewith the hard data it needs to meet regulatory
offices may be adequately protected through anrequirements.
access control list on a router, while larger officesEliminating Tunnel Vision
might want to provide another layer of protection withKey to a true multidimensional, in-depth managed
a separate firewall and intrusion prevention sensors.security solution is the ability to tightly integrate
This not only prevents attacks from untrustedmanaged security services with a Security Information
networks but can keep infected internal systems fromManagement (SIM) infrastructure. SIM tools enable
perpetrating attacks. The next layer of protection cancorrelational analysis across multiple hardware
be applied to resources; critical web, mail, file, database,platforms in all layers of the network and across all
and other servers should be directly monitored againstsecurity devices, enabling a complete and holistic view
compromised by the rare attack that can make itof the security posture of every managed device. This
through all the other layers of protection.eliminates the tunnel vision associated with looking at
Finding the Right Providerthe output of just one device and enables a much
Using several layers of protection in multiple dimensionsdeeper and broader view of all security events across
of a network is necessary because threats can comethe entire business network. The reports generated by
from anywhere. Yet service providers focus onthe SIM can also be tailored to present ongoing
protection of the perimeter and Wide Area Networkcompliance data for regulatory audits such as SOX
(WAN) while MSSPs focus on the perimeter andand Health Insurance Portability Accountability Act.
Local Area Network (LAN). Neither looks effectively atThe End Result: Comprehensive Security
all the dimensions required to enable businessVNOs with a SIM infrastructure can provide the most
connectivity. The most complete solutions providecomprehensive view of the network, correlate events
security across the entire business network, inclusiveamong a wide array of network devices, and identify
of each individual remote user, all remote offices,and address security events on a global scale in a
every partner connection, and all primary links. Missingmatter of minutes. Enterprises of any size can receive
a single piece can lead to exposure of the entireimmediate data on security vulnerabilities across the
network.entire network, down to the individual user. And these
Virtual Network Operators (VNOs), can offer a fullenterprises know their extended network is receiving
suite of managed security services and deliver themthe broadest, deepest protection possible.