Advance Persistent Threats are a challenge to any IT organization. Security’s rapidly changing landscape makes the problem that much more difficult. Brent Conran, CIO and CISO for the U.S. House of Representatives, gave a presentation on APT at The IMF Fall Sr. Executive Roundtable in Baltimore back in October. He spoke about security operations today and provided some counter measures to combat these threats. Below is a brief excerpt from the presentation’s report on the advantages of tiering your organization’s network (Download the full IMF Report here):
“If your organization has a flat network you should really consider moving away from it. You constantly hear about the need to be agile these days. The reason a lot of companies are not agile is because they have these large flat networks. If you want to put a new piece of technology in you have to perform your risk evaluation process based on the entire network. If you tier your network (fig. 4 page 11) it allows you to look at stuff on the internal enclaves as a different risk model than perhaps something out in the DMZ. The House has tiered a lot of their networks now. They have made the decision to let people do a lot more in the middle or out in the DMZ but they are going to be extremely cautious about anything that enters those internal enclaves. The enclaves contain the payroll system, HR system, and Remedy among other things. They have found that utility architecture saved a lot of money because they are not building point solutions each time. If a new technology is introduced with a web tier, app tier, and data tier it can snap in pretty seamlessly because the infrastructure is already in place. In other words you are just integrating a new application as opposed to buying all of those components.
At this point your conversations will focus on needs and fees, not the cost of building a new point solution. This tiering system has helped the House of Representatives become more agile and benefit its members, staff, and constituents. They receive better information because when a new technology becomes available IT will let it go a lot easier. The House recently installed Skype but without that tiered network environment it probably would have never happened. With that tiered architecture they were able to push a lot of stuff further down into their enclaves, thus making it much easier to bring in Skype…”
Join us this February for our Sr. Executive Retreat at One Ocean Resort Hotel & Spa in Atlantic Beach, FL. Visit the meeting page for more details or view the current agenda.