You are here: silicon.com > Software > Security Strategy

Security Strategy

Leader: No respite from security headaches

Businesses must - still - always be on guard

Tags: sans internet storm centre

By silicon.com

Published: 15 November 2006 18:05 GMT

It is the job of any security professional to exercise constant vigilance. Bodyguards, for instance, are trained that way. And IT security pros are no exception.

But this is made all the more difficult when new vulnerabilities are popping up all the time - sometimes undetected for months or weeks. Now even less than a day is enough time for a hacker to exploit a new software hole.

The SANS Institute today published a list of the top 20 targets for hackers - which included the likely suspects of Microsoft applications and Windows along with Mac OS X and Unix.

Interestingly the same technologies that were causing problems years ago are apparently still a headache.

VoIP phones, for example, made the top 20 list, even though the warnings over VoIP and advice on how to secure the IP networks have been around for years. P2P applications and media players were also named, though they've been threats for at least the past five years.

We're obviously not making too much progress in securing these technologies.

One of the biggest problems with software, according to SANS, is that vendors are selling incomplete applications. For an application to be secure, constant updates are required. This process takes up considerable time for the IT departments responsible for testing and deploying those updates. Some companies have even dedicated patching staff, who clean up the mess left by the vendors.

After reading the SANS list, an IT user would surely ask: so which software or technology can I use? Given that Windows, Mac OS X and Unix all have vulnerabilities, it's a situation of choosing the lesser of three evils.

So the list serves some use as a guide on what to watch out for. But it does little to help a business feel confident its systems and networks are secure - for that, you still need that continual vigilance.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Penetration Testers Required - Must be CREST / CHECK Accredited

Overview • To work in their security testing team, you will need a strong technical background in the area of network security including a ...

Security Operations Centre Manager (SOC Manager), SC Security Cleared

You will be responsible for all security incidents, incident response, IDS analysis, threats and tracking vulnerabilities of the infrastructure.Due ...

Security Operations Engineer

Knowledge of system security vulnerabilities and remediation techniques Follow standard practices and procedures to respond appropriately to external ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: