You are here: silicon.com > Networks > LANs

LANs

Your perimeters are "porous", companies told

'You know that expensive firewall I bought last year? Well, it's no longer enough'...

Tags: perimeters, lans, security, network security

By Tom Espiner

Published: 28 April 2006 08:35 BST

Security professionals have been advised to accept that organisations' perimeters are now open, and to start designing future systems architecture to account for this.

In a debate at the Infosecurity conference in London on Wednesday, security experts argued that maintaining security at the boundaries of an organisation had become unworkable, thanks to an increasingly mobile workforce, internet interaction with customers, partnership programmes between organisations, and third party contractors who work and communicate over the web.

From an architectural perspective we have to start thinking away from the perimeterised paradigm.

Paul Simmonds, global information security director for ICI, said: "As organisations, our perimeters are becoming more and more porous.

"Hackers target email and web applications to get into the organisation. We have umpteen people managing our systems - contractors, who themselves sub-contract, probably to India. Deperimeterisation has happened whether you like it or not."

Deperimeterisation - where the security emphasis is moved from the edge of the network and onto individual devices, and ultimately to individually encrypted data packets - became a fact for ICI with increasing employee mobility, Simmonds argued.

He said: "ICI has 6,000 laptops roaming around the world. The bottom line is that they are connecting outside of ICI's closed environment. This is the industry's dirty little secret - 'You know that expensive firewall I bought last year? Well, it's no longer enough'."

Nick Bleech, IT security director for Rolls Royce, said security professionals should not drop their current perimeters but instead should plan for the future.

Bleech said: "This is about the next five to 10 years. From an architectural perspective we have to start thinking away from the perimeterised paradigm."

Both Bleech and Simmonds are members of the Jericho Forum, a group of blue-chip companies that advocates security through deperimeterisation and open standards. BP, another member, is putting its laptops directly onto the internet rather than its local area network.

On the other side of the debate, Mark Waghorne, principal adviser for KPMG, argued that in fact there was no such thing as deperimeterisation, and that instead organisations should redefine their boundaries.

Waghorne said: "If anything, the world is heading towards reperimeterisation. You have to look at how you manage your assets. To suggest the only sensible architecture needs to be built on the deperimeterised paradigm is irresponsible. Would you put your trading, or process control network on the internet?"

Bleech replied that organisations' supervisory control and data acquisition systems (Scadas) are already vulnerable to attack because they link to web-facing business systems.

He said: "The reality is Scada systems have 12 different business systems feeding into them."

Dan Blum, senior vice president and research director for Burton Group, disagreed, and said deperimeterisation was not an architecture but rather a process. "In many cases we're being forced to deal with a sub-optimal situation," said Blum. He recommended perimeterising "zones of trust" for the enterprise.

Blum added: "We have a restricted zone for the backend, a protected business zone, and an outer zone allowing access to the net. These perimeters are maintained by dedicated firewalls. You can control data flow and use between the different zones."

The debate ended with a vote from the audience of security professionals, who overwhelmingly agreed that responsible security architecture should be based on deperimeterisation.

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Steve Ranger Editor's Blog: Back to the future What will remain of today's technology in 100 years?

Peter Cochrane Peter Cochrane's Blog: Autosync, at last Now we just need it to meld with remote control…


  • Jobs
Orchard ArcHouse Business Systems Analyst

My Client is urgently seeking a Business Systems Analyst with extensive experience using Orchard Archouse Housing Systems. Experience in other ...

Infrastructure Architect

Led by a high performance management team, our IT team consists of innovative professionals working together to deliver IT solutions that provide a ...

Technical Project Manager - Business Systems

Led by a high performance management team, our IT team consists of innovative professionals working together to deliver IT solutions that provide a ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: