A day in the life of superhighway cops

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

A day in the life of superhighway cops

Post by Tami »

A day in the life of superhighway cops
By MARK BLANCHARD
Special to The Globe and Mail



When a guest checks into a hotel room with a computer virus, Vineet Gupta and his team are ready.

''We constantly watch what they bring in,'' explains the vice-president responsible for technology at Fairmont Hotels and Resorts, the Toronto-based company with 44 properties across Canada and around the world. ''When it happens, we talk to them or they call in if they're having problems. Obviously, we can't take the chance that it'll get out.''

In addition to a firewall designed to stop unsuspecting road warriors from comprising network security, Fairmont monitors its corporate network and separate in-room guest networks. That, the company believes, gives it more flexibility, greater control and increased security and service for guests than an outsourced provider would offer.

"It's a challenge," Mr. Gupta admits. "We try to take the preventive approach rather than fix something afterward. The sheer cost of cleaning it up after the fact is high."

Fairmont has information technology staff in Toronto and Calgary who watch the two networks around the clock. They also update patches, monitor their networks for threats and help hotel guests and employees who call with problems.

Keeping a corporate network with hundreds or thousands of users secure and up to date with the latest virus definitions and patches is far more difficult than taking care of a single computer at home.

Every day, IT staff have to sift through and prioritize security alerts from software and hardware companies, managed services providers and respected independent sources, such as the CERT Coordination Center at Carnegie Mellon University's Software Engineering Institute, set up in 1988 to deal with security issues on the Internet.

One of the problems is that when vendors release software patches, small pieces of code meant to fix problems, they also often announce vulnerabilities.

The moment a vulnerability becomes public knowledge, hackers begin writing programs to exploit it while IT departments begin the laborious process of patching their networks.

The process is automated for the most part. But most organizations will roll out a patch in a "test environment" first, assessing how critical applications perform with the patch before it is introduced across the enterprise. Yet time is not on their side. Today, they have on average less than a week before a hacker can strike.

Experts say that's simply not enough time for most organizations, especially if they have mobile workers who are away for weeks with their laptops and there are hundreds of devices -- computers, servers and firewalls -- that need patching.

Unlike most businesses, Fairmont sees thousands of new users and their laptops log onto its high-speed Internet access each day, only to be gone the next -- replaced by others. So perhaps there's no better example than a hotel's transient population to show that network security isn't just about technology.

"Network security is about people and people understanding the value of the assets that you want to protect," says Ron Ross, Bell Canada's chief security strategist. "The technology is able to keep up with the latest in viruses, attacks and that kind of stuff but it's as simple as end users not being educated in terms of: If they get an e-mail, don't open up that attachment" unless you're sure it's safe.

Mr. Ross suggests that the old mantra of "people, process and technology" has been forgotten by more than a few IT departments focused on spending money on new software or hardware.

"There's lots of great technology out there," he says. "But there's still that whole awareness and education thing. Once you build the processes, you have to implement the processes and there's no technology available today that automatically does that for you."

The people, process and technology must be integrated, not isolated, and in line with an organization's business objectives, Mr. Ross adds. Whether a company sells its products or services on-line or in a store, it depends on its network to perform real-time transactions, track inventory and hold customer information -- valuable data that must be secure and transmitted with ease.

Martin Thibodeau can appreciate that. As vice-president of information technology at La Senza Corp., the Montreal-based lingerie and sleepwear retailer, he understands all too well people are an important part of network security.

But Mr. Thibodeau notes that some people get frustrated by the restrictions IT departments impose to maintain higher security.

Like many organizations, La Senza blocks staff in its stores, distribution centres and head office from accessing instant messenger programs and Internet e-mail sites, such as Hotmail.

"We block people from going there, but people are frustrated because they don't understand. Maybe it's our fault we don't advertise it enough and don't tell them why we're doing this, but it creates a lot of calls to the help desk."

IT departments are challenged enough dealing with changing technology, let alone user complaints. "It's resource-consuming and time-consuming -- big time," Mr. Thibodeau notes.

"Before, you simply had a network manager controlling the firewalls and setting the rules. Now you find yourself having a person acting as a security officer to deal with antivirus patches, antivirus updates, firewall patches and firewall updates," he adds.

"People don't understand why it is so difficult to just send a simple e-mail out or get an e-mail in. Whether people like it or not, it supports the business -- all of our credit and debit transactions goes through that network."

[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20041007.gtsrhelp07b/BNStory/Technology/\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Jim
Administrator
Administrator
Posts: 1324
Joined: Thu Jun 17, 2004 12:37 am

A day in the life of superhighway cops

Post by Jim »

Sounds like a hard job...but fun. I know how that stuff goes, not much to it really just need time and software <img src=\'http://www.killanet.net/forum3/public/s ... >/blum.gif\' class=\'bbc_emoticon\' alt=\':P\' />
Love is all a matter of timing.

It's no good meeting the right person too soon or too late.

If I'd live in another time or place...

...my story might have had a very different ending.
Post Reply

Return to “Security”