Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Skype Worm Hits Windows | Main | Oracle Security for Web Developers »

Unified Threat Management (UTM) at the Enterprise Scale

The market in unified threat management firewalls is maturing and according to a Network World article by Joel Snyder, titled UTM Firewalls:Ready for the Enterprise, they're not just for the small and mid-sized market anymore. I don't have an argument with his findings, I think the big hurdle for UTM vendors is overcoming organization's structures. The people responsible for AV aren't the same ones responsible for firewalls or URL blocking. Yes, there are a lot of advantages to working with a single console and the quality of some of the components are as good or nearly as good as stand alone products, but how can you convince three or four groups in the IT department of that?

Snyder points out:

This single management view is especially valuable when firewall, VPN and IDS/IPS are considered together because all three of these functions act on the same policy. Each of these functions needs to have some view of the topology of the network, what applications are running on different servers and what different groups of users are allowed to do. Completely separate management for all three functions makes coordinated policy maintenance difficult, if not impossible.

A single UTM-ready management console realistically enables a fine-tuning of policy across all three functions, increasing total security.

It makes sense in small and mid-size businesses but I'm not sure how long it will take to shift responsibilities and ways of thinking about security management to get big organizations to buy into UTM.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/419

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net