Greg Young

A member of the Gartner Blog Network

Greg Young header image 4

Entries from September 2008

Get Rich Quick With Network Security

September 30th, 2008 · 12 Comments

Get a glass jar or empty coffee can and a marker. 
Write on the container in bold letters "Security Silly Jar: $0.25".
Have people put a quarter in the Security Silly jar every time they say:

‘UTM’ and ‘Enterprise’ in the same sentence.
in fact, anytime they same UTM.
Manage and Threat in the same sentence.  Besides [...]

[Read more →]

Tags: Uncategorized

McAfee Announcement to Purchase Secure Computing

September 29th, 2008 · 1 Comment

See the analysis in the Gartner First Take here regarding the network security impacts.  We also have a separate First Take on the Secure Web Gateway aspects of the events here.
Anyone who says that there will be a new buying center created from the convergence of host security and network security has to put a nickel [...]

[Read more →]

Tags: Security Events

The Most Expensive Decision You Make In Network Security Isn’t About A Product

September 29th, 2008 · No Comments

DMZs are expensive to begin with.   It is remarkable the growth in the amount and variety of security equipment we need provide web access, send emails, and give staff access to some information the need: multiple firewalls, IPS, anti-spam, anti-virus, SSL termination, web application firewalls, SSL VPNs, … a lot of expensive stuff.   This is the [...]

[Read more →]

Tags: Security

Do You Need One Firewall Vendor or Two?

September 26th, 2008 · No Comments

A high number of client inquiries I receive are around DMZ redesign.  This is the hardest task in network security you can undertake because there is no one-size-fits-all DMZ design and there are many moving parts in play.  The good news is that getting the DMZ right will likely be one of the most beneficial [...]

[Read more →]

Tags: Security · Security Research In Progress

Little Fibs, Big Fibs, and Datasheets

September 25th, 2008 · No Comments

A lot of the datasheets for network security products have made it really hard for customers to conduct an apple-to-apple comparison.  I’m not talking about the overall IT industry practices with datasheets.  In the last 24 months, especially in the areas of firewall and IPS throughput,  a number of companies have started listing uninspected port throughput as the [...]

[Read more →]

Tags: Security

Honeypots No More

September 24th, 2008 · No Comments

It used to be that having a honeypot was a sign that you had good IT security.  The reverse is now the case.  When the threats went from motivated to automated, determining if you are a target is not that valuable.  Everyone is now equally a target, and the threat is persistent.
Your network is now [...]

[Read more →]

Tags: Security

Infrastructure Protection Hype Cycle 2008 is Finished!

September 23rd, 2008 · 2 Comments

(whew) 
The 2008 Hype Cycle for Infrastructure Protection presents a significant change from the previous edition.  Several technologies have been obsolesced, some new ones included, and some have been merged together.  Like a game of king of the hill, the top of the peak of inflated expectations is somewhat unoccupied but both slopes are crowded. One side with [...]

[Read more →]

Tags: Uncategorized

Kafka’s Acceptable Use Policy

September 22nd, 2008 · No Comments

If you work in IT security and haven’t read Franz Kafka’s The Trial, you need to.  One of the themes from the novel is that when the rules are unclear, authorities have only as much authority as you give them.  This doesn’t make for good law or security.  Although life is full of gray areas, you should minimize them when [...]

[Read more →]

Tags: Security · Security Events

Security Making Faster Networks

September 22nd, 2008 · No Comments

Security geeks love tired old metaphors and saws.  Often these are used like a threatened octopus spouting ink to confound opponents and provide intellectual cover to escape under, but sometimes they are helpful.
One oldie but a goodie is that “brakes don’t help you stop, they make it so you can go faster”.  Good network security let’s the business [...]

[Read more →]

Tags: Security

We Don’t Just Assess Security Products…

September 20th, 2008 · No Comments

…we also assess the companies that make and deliver them. 
I could have ended things there and have this be a really short post, but let me expand on this.
After you buy the security product, you pay on average about 20% per annum for support.  And you use that support and have interaction with the vendor.  And you [...]

[Read more →]

Tags: Uncategorized