Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 9 June 2010

How the principles behind Lego can assist IT managers in their quest for better IT security

Posted on 04:32 by Unknown

by Reuven Harrison, CTO of Tufin Technologies

As a boy, like many lads of my age, I loved Lego - I'd use the red, green, blue, yellow and white bricks that, in those days, came in just a few shapes, to construct houses, ships, cars and stairways that led absolutely nowhere.

Lego - for small boys - as it is today, is all about fun and imagination.

In mid-April, Tufin's team had the good fortune to attend Check Point's annual European customer and partner event, the Check Point Experience, in London.

At the event, which was attended by the great and the good in the world of IT security, we demonstrated our workflow technology.

Because of the high calibre of the professionals attending the event, it was a delight to meet industry colleagues both old and new, and explain how we see the changing IT security puzzle to the professionals at this event.

During the event I was struck how infosec has matured. Many companies are now approaching security as an integral part of IT which requires proper management and the business processes around it.

In many ways the approach to building models as a boy that Lego engendered is the approach that is needed in the modern world of IT security - a set of building blocks, in different shapes and colours, that can be combined to build an effective IT security process.

The `building block' principle is nothing new in the world of network computing. It's a similar approach that taken by developers of the `C' programming language back in the 1970s when Bell Labs came up with the then fledgling Unix programming language.

C's minimalist approach allowed early software developers to develop quite complex programs by taking a modular approach to program development.

Within a few years of C's release, libraries of simple C routines were developed that, like Lego bricks, could be combined to produce quite spectacular software capable of doing a great deal with quite limited memory and processor facilities.

Fast-forward 38 years to the Check Point Experience, and there are my team and I, explaining how a modular approach is the only way that security processes which differ so widely from one organization to another, can be supported by a generic workflow solution..

After a couple of year's detailing Tufin's IT security solutions to the great and the good, and not just at the Check Point event earlier this month, I have realised that there is no such thing as a standard process for managing changes to the security policy of an organisation.

For example, whilst one organisation starts off with an access request which is then approved by a line manager, another may first want to design the change and only then approve it.

If you extrapolate the Lego `building block' approach to the security policy issue in most organisations, it's clear that a modular methodology can pay dividends when the requirement to deviate from normal procedures is required.

As another example, some professionals want to allow requesters to specify the target firewalls, whilst others keep them strictly within the domain of the firewall operations group.

In an ideal world, it would be down to the IT professional to issue the dictum - "here's how you should be working" - and provide one ideal process for managers to implement.

As any IT professional will know, however, this ideal cannot work, as the principal of `one size fits all' does not work with IT security - every organisation has developed an often unique set of processes that match their needs, organisational structures and policies.

In addition, beyond the obvious technical constraints, it's clear that there are also social and political factors that have shaped these processes and these cannot be modified very easily.

But there is a solution - and once again the modular principals that millions of small boys the world over have adopted with Lego blocks also apply to the grown-up world of IT security.

And flexibility also comes into play here, as instead of a single rigid process, companies like ours have opted to provide its clients with a variety of small security building blocks that can be compiled into the organisational process.

These building blocks are designed around permissions and roles; users and groups; workflows composed of configurable steps; and forms that consist of configurable fields such as input fields and drop down lists.

Other `Lego blocks' include access flow descriptions that can change their appearance to match the needs of users with different roles; and dynamic but controllable workflows so that users have flexibility within a fixed framework.

This modular approach has been well received amongst the end user community, who appreciate the building block approach is highly effective in a variety of environments with differing processes, including those situations that management have not yet seen - or anticipated.

Now I'm back from the exhibition and conference, I'm back to playing with real Lego with my daughters - who enjoy their building blocks every bit as much as their male peers - and am building princesses and castles, rather than the cars and ships of my boyhood.

And just as Lego can be flexible enough to meet the disparate building needs of little boys and girls everywhere, so I've concluded that a `building block' approach to IT security and lifecycle management can help customers create their ideal security protection.

And just like my Lego analogy, by allowing IT professionals to create their unique set of IT security processes - and processes that are almost infinitely customisable - allows the rest of the organisation get on with its core business of making a profit.

As a small boy Lego taught me a lot. Now I'm a bit more grown up, the principles I've learned from Lego have helped shaped my professional approach to security.

Now where did I put that Meccano set?...

www.tufin.com

Courtesy: Eskenzi PR

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ▼  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ▼  June (22)
      • Half of organisations expect cloud to enable creat...
      • EU Code paves way for ‘Data Centre 2.0’
      • Data storage and encryption specialist iStorage re...
      • Data storage and encryption specialist iStorage re...
      • Proprietary software 'a waste of money', says EU c...
      • Imperva CTO says Patch Tuesday only resolves discl...
      • Unencrypted removable storage devices pose company...
      • Critical Adobe flaw about
      • Imperva applauds IIA plans to quarantine zombie-in...
      • New ISACA guide helps enterprises create an effect...
      • Top Five Social Media Risks for Business: New ISAC...
      • Introducing FalconStor® Continuous Data Protector ...
      • Survey reveals that 1 in 10 IT professionals admit...
      • How the principles behind Lego can assist IT manag...
      • Survey finds HMRC breach recommendations being ign...
      • UK cloud computing market 'to double by 2012'
      • Trusteer CEO says Google switch is not a recommend...
      • The Guardian’s Classroom Innovation - in associati...
      • Keylogger sophistication rising as criminals look ...
      • IT Professionals Are Hacking Their Own Enterprises...
      • Expert urges 'revolutionary' IT leaders to step up...
      • Experts warn about risks of multi-tasking on new i...
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile