You are here: silicon.com > Software > Security Strategy

Security Strategy

Logic of Logical rubbished

Too many firewalls spoil the fun...

By Heather McLean

Published: 12 October 2001 12:15 BST

A top Ovum analyst has rubbished the growing security trend for splitting corporate departments into firewall-wrapped security zones

Graham Titterington, corporate network security analyst at Ovum, stated the zoning method of dissecting enterprises into specific departmental zones - as recommended by IT security consultancy Logical - is not economically viable and will block business processes.

Titterington said: "Putting barriers up between departments is getting in the way of business processes and I've never come across a company that needs to defend at a departmental level.

"Presumably this method is to increase the market for firewalls. I don't think Logical has got its strategy right."

Simon Clifford, consultant with the Logical security practice, said: "Users themselves are the biggest risk and they need to be protected. That's a good enough reason for them to be zoned off."

But Clifford added Logical has to be careful not to zone too much and cut the user off from file and print services and admitted his ideal recommendation of a firewall pair and intrusion detection around each department was expensive.

Clifford said: "The costs are prohibitive and it's painful to split the physical fabrics of a company. Zoning architecture will increase initial spend on IT, log traffic between zones generated by more firewalls and intrusion detection systems will quadruple.

"The time spent by the person that consolidates log files and watches for intrusions will increase according to the number of security policies added."

Gunter Ollmann, principle consultant at ISS, said overheads will definitely rise because of equipment, licensing costs of individual firewalls and the time taken to monitor the tools.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Application Architect

Communication Skills : Applied English: Fluent Additional information Candidates for Data Architect role will have the following knowledge and ...

S&P (Security) IT Specialist

Non Technical skills - Security methods and practices - Data encryption technologies and products - Operational security and trust models - Physical ...

Network Security Administrator Level 2 (CCNA, CCNP)

Regularly troubleshooting customer IPSEC client and site-to-site VPN connections - Candidate will also deploy Cisco IDS sensors and configure monitor ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: