Keeping Your Data Secure

Businesses around the world are being bombardeddirectly on the platform to be protected, rather than on
with sophisticated threats against their data anda security appliance designed to filter the content and
communications networks every day.serve as a buffer.
As enterprises invest heavily in fortifying their ITManaging Security Level - making sure all the
infrastructures and enforcing comprehensive andcomputers have installed the latest security updates
constantly upgraded security policies against maliciousand enforcing a unified security policy can be very
code attacks, another home-grown threat - the mobiledifficult. When the computers themselves are at the
workforce - is opening the floodgates to compromisedfrontline, these security weaknesses can be disastrous
enterprise data and corporate network contamination.to the entire network. In other words, it's "all or nothing",
Though mobile working offers gains in commercial andeither the entire network is secured or nothing is
operational value, enterprise security policies often stiflesecured.
the effectiveness and productivity of mobileConsequently, many organizations adopt tough security
workforce devices.policies prohibiting most wireless networking options
Here we examine why best of breed softwares, in(significantly limiting user productivity and remote
isolation, are not able to provide the mobile workforcecomputing freedom), or imposing strict, costly and
and their laptops with the same high level securitydifficult to enforce cleansing procedures for laptops
afforded to office based workers.that return from the "field".
Two lines of defence in a protected corporateBest of breed software made mobile
environmentA growing number of CSOs have decided to place
Currently organisations anticipate, detect, and preventcomputers behind a robust security gateway, usually a
threats from laptops attacks via a layered approach.dedicated security appliance, to counteract the current
This is coupled with centralized, uncompromising ITweaknesses in laptop security.
policy which overrides an individual's control over hisUnlike PCs, these appliances are equipped with
her own laptop.hardened operating systems that do not have security
As IT departments prioritise corporate IT governance,holes, "back-doors", or unsecured layers. They are
their primary method of effectively enforcingdesigned with a single purpose, to provide security.
organizational security policies is by controlling allThe fact that these security appliances are
networking components.hardware-based and not software-based provides the
When connecting to the Internet from within thefollowing advantages:
corporate network, laptop users are protected by twoCannot be uninstalled - security attacks often start by
lines of defence:targeting the security software, and trying to uninstall it
A comprehensive set of IT security appliances runningor to stop its activity.
secured and hardened Operating Systems, andSoftware-based security solutions, as any software
security software including firewalls, Intrusionprogram includes an uninstall option that can be
Prevention/Detection System, antivirus, antispyware,targeted.
antispam, and content filtering, all of which areIn contrast, appliance-based security cannot be
completely controlled by the respective corporate ITuninstalled as it is hard coded into the hardware.
organization.Non-writable memory - hardware-based solutions
Personal firewall and antivirus software installed on themanage the memory in a restricted and controlled
user's laptop and controlled by the user.manner. Security appliances can prohibit access to its
In addition, when laptops are within the protectivememory, providing greater protection against attacks
corporate environment, the organization's ITon the security mechanism.
department can exercise full and consistent controlThe use of hardware allows the combination of a
over (and visibility of) any device, which is a criticalcomprehensive set of security solutions in a single
operational consideration. This means the IT teamdevice.
can:consistently update respective laptops with data,Hardware also allows the combination of
policies, etc.monitor the entire network effectivelybest-of-breed enterprise-class solutions with
vis-?-vis the status of all network components.proprietary developments working on both the lower
Outside the safe zoneand higher levels (e.g. packet and network level,
Once a laptop starts 'roaming' outside the enterpriseapplication level etc.).
governed network, the 2-line defence system noIn addition, the well known tension between users and
longer applies, as the laptop is essentially no longerIT managers over their computing freedom can be
protected by the corporate security appliances layer,overcome via hardware.
and is exclusively dependent on the security softwareOn one hand, users want to have complete freedom
installed on the local operating system.when using their computers, while on the other hand, IT
The roaming laptop is exposed to potential threatsmanagers try to enforce security policies (e.g. banning
from nearby wireless and wireline devices (in hotels,the use of P2P software).
business lounges, airports, WiFi at Internet Cafes, etc.).By using a security appliance, IT managers solve the
These threats signify a danger far beyond the scopeconflict between the user's desire for computing
of the individual laptop, as intrusive code may proceedfreedom and the IT manager's desire to control and
to use the laptop as a platform for breachingenforce security policies.
corporate security, once the laptop had returned to itsWith software, policy is part of the laptop or computer,
base, and is connected to the network.whereas through an appliance security policy can be
Relying solely on the best of breed software on theenforced outside the laptop and the user has complete
laptop is flawed due to:freedom inside the safe computing environment.
Operating System Inherent Vulnerabilities - by definition,In conclusion, to provide corporate level security for
security software running on Windows is subject tolaptops operating outside the safe office environment,
inherent Windows vulnerabilities, effectively exposingCSOs should consider layered security architecture on
personal firewall and antivirus applications to maliciousa hardware appliance.
content attacks.A dedicated appliance can hold all of the best of
Unknown Threats - the security software can onlybreed security softwares, and is able to re-introduce
defend against known threats. By the time thesethe two lines of defense enjoyed by office based
threats are added to the knowledge base, it may bePCs.
too late.By introducing a security gateway, should security be
Immediate Damage - malicious content executesbreached, the damage stops at the gateway.