Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« No More Justification Needed: It's Time for Content Filtering | Main | Unsecure by Default »

Gates Focuses on Security Fundamentals at RSA

At their keynote address to the RSA conference yesterday, Bill Gates and Craig Mundie made a number of points that are welcome and long awaited.

First, the recently released Vista and MS Office 2007 were built from the start using the company’s security-conscious software development methodology. This is important because security is a function of the structure of a system, not a feature that can be added on later anymore than you can provide structural integrity to a building by adding a room.

Second, there was a recognition of the demise of the network perimeter as the dividing line between "us" and "them." Remote users, business partners, and customers outside the firewall now need as much access to IT assets as those inside the perimeter. The new solution is security by policy not topology according to Gates. Agreed.

Next, IPSec and OpenID are part of Microsoft's long term strategy. The good news here is that the company is not trying to go its own way with proprietary standards. The days of days of MS setting the agenda and others following are over.

Gates and Mundie recognize there are still plenty of challenges ahead. There was a lot of talk about object-based security. For example, a document should have embedded authorizations that allow and disallow functions according to policies defined by the owner, not based on where it sits on the network server.

This model works with fairly course grained objects, like documents and media files but not others. The amount of data in fine-grained objects, like a transaction in a database can be many times smaller than the authorization data needed to protect it. Encryption and host security is still the best protection for these fine-grained objects. Perhaps we'll see a lightweight mechanism for storing minimal authorization information developed for database transactions.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/213

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net