Skip to main content


Confidence in corporate security shattered by misconfigured Firewalls

posted onJuly 27, 2001
by hitbsecnews

Only two out of 50 firewalls at a leading Swiss bank were configured correctly -- just one instance of security that is all that it should be Network security is being overestimated by IT managers because they are failing to manage protective software properly, according to a security expert.

Norbert Pohlmann, a director at Internet security specialist Utimaco and author of a new book entitled Firewall Systems, said the mismanagement of software is putting firms at risk. "We recently found that only two of 50 firewalls at a leading Swiss bank were functioning as they should, while the rest were configured incorrectly," said Pohlmann. "IT managers still don't seem to understand the risks. They spend money on security products and fail to manage them. Companies need to understand security at a conceptual level to reduce risk, as there are so many threats out there such as viruses, hackers and so forth."

IT managers still overestimate security

Pohlmann recommended that the management of security systems should only be carried out by trusted personnel or outsourced to specialists. "The deployment of [security products] requires that the users be trained properly," he said.

In a recent survey of 445 IT directors attending the IT Directors' Forum 2001, just under half said firms should appoint a dedicated digital security expert, compared with 31 percent who opposed this approach.

Analysts said IT managers find some products particularly difficult to configure and control, and manageability rather than price should be the main concern when buying a firewall product. José López, lead analyst for European network security at industry watcher Frost & Sullivan, said, "IT managers should not base their choice of firewall on price, but should test products to find the right one for their organisation.

Firewalls are something you must get right from the beginning." López also criticised a number of manufacturers for their emphasis on functionality. "Some vendors focus on adding competitive capabilities to firewalls over ease of management," he said.

There are a number of security-policy management solutions available to simplify the provisioning and management of firewalls, switches and routers.

SNP.

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th