Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, March 25, 2010

Business Online Collaboration Dichotomy


The goal of creating a collaborative enterprise might seem like an essential requirement that all forward-looking business leaders would actively support. However, fear of the unknown sometimes makes intelligent people react in ways that, in hindsight, appear totally illogical.

A case in point, Cisco announced results of a global study that found that while 77 percent of IT decision makers surveyed plan to increase spending on internal collaboration tools, company employees believe that their ability to collaborate is constrained by their own employer policies.

That said, more than a quarter of those who work at organizations that prohibit the use of social media applications admitted to changing the settings on their corporate devices to gain online access -- claiming they "need the tools to get the job done."

This new insight was attained by investigating practices at medium to large enterprises -- those with more than 250 employees. The study, conducted by InsightExpress, surveyed 2,023 corporate end-users and 1,011 Information Technology Decision Makers (ITDMs) from 10 countries.

Progressive Use of Online Collaboration Tools
The research found that ITDMs around the world recognize the importance of collaboration tools to the future success of their business, with India and China being the most progressive in adopting the technology.

Consequently, many ITDM respondents said that they are planning to increase their spending on collaboration technologies over the next year, identifying video conferencing, Web conferencing and IP telephony as primary areas of investment.
  • Globally, 96 percent ITDMs and end users recognize that collaboration tools have a role to play in the future success of their business.
  • Of those surveyed, 77 percent of ITDMs expect investment in collaboration tools to increase between now and October, and 56 percent expect their spending on collaboration tools to increase by 10 percent or more.
  • Productivity and efficiency were identified by both end users and ITDMs as the primary benefits of increased collaboration -- with 69 percent of end users regularly using advanced collaboration tools, such as video and Web conferencing, to help them complete tasks at work more efficiently.
Why Employees Defy the Policy Restrictions
Employees identified a variety of frustrations with devices and applications at work. These include restrictions set by IT managers on the types of collaboration technologies that can be used at the workplace, a lack of integration among the applications, non-compatible formats (video, data, voice), and the limited number of collaboration tools at their disposal.
  • Slightly more than half (52 percent) of organizations prohibit the use of social media applications or similar collaboration tools at work.
  • Half (50 percent) of the end users admit to ignoring company policy prohibiting use of social media tools at least once a week, and 27 percent admit to changing the settings on corporate devices to get access to prohibited applications.
The study also highlights how end users are clearly motivated by the benefits gained from increased collaboration, but also identifies a need for some enterprises to adapt their corporate processes and organizational culture.
  • When asked to identify how collaboration benefits them, 45 percent of the end users pointed to improved productivity and efficiency, 40 percent noted they receive assistance in solving work-related problems, and 31 percent enjoyed accelerated decision making.
  • Ease of use (58 percent), the ability to communicate anywhere and at any time (45 percent), and features and functionality (37 percent) are the three most desired attributes of a device or application.
  • End users believe that elements of corporate culture can inhibit their ability to collaborate successfully: 46 percent feel that all decisions are made by people at the top of their organization, and 39 percent say colleagues are not willing to share information when it does not benefit their own business unit.
The research is the second of a two-part series that Cisco has commissioned to explore the impact of social networking and collaboration in the enterprise. Cisco previously shared findings that explored how organizations use consumer social networking tools to collaborate externally.

Thursday, September 3, 2009

Infrastructure as a Service, in Action


A West Chester, PA-based company was searching for IT help, to more effectively and securely distribute confidential and proprietary content to its customers. Enter Verizon Business, with its managed cloud service offering.

Modevity, LLC will use Verizon Computing as a Service (CaaS), an on-demand, flexible solution that allows businesses to harness cloud computing to better manage IT resources and deliver performance and security that supports their growth.

Better Alignment of Financial and Human Capital
In addition to these benefits, Modevity expects to see a significant positive impact on the company's bottom line as a result of embracing this managed cloud service offering.

"We are focused on continuing to grow Modevity in a smart way by making key resource decisions in terms of capital and staffing expenditures," said Tom J. Canova, co-founder and chief marketing officer for Modevity.

"Moving to a virtual environment with Verizon Business allows us to consolidate our existing server hardware and software, and eliminates future purchasing and licensing costs in that area. It also allows us to add more staff in key areas -- all while maintaining consistent, reliable service to our customers."

Complete IaaS Platform Solution
Verizon Business is providing Modevity with a comprehensive cloud-computing environment, supplying server hardware, bandwidth, load balancing, firewall network security, backup and managed services to support the Modevity ARALOC Content Rights Management hosted solution.

Modevity can now rely on Verizon's out-tasked secure and available Infrastructure as a Service (IaaS) offering. This frees up Modevity to invest in more strategic product development, research and development, and customer support initiatives.

"With Verizon Business as its partner, Modevity can grow its business strategically while relying on us to seamlessly power its customer applications," said James Geary, vice president of Verizon Business SMB sales. "Our world-class CaaS solution will allow Modevity to drive more value from its computing resources while controlling costs."

A key consideration in the selection of Verizon Business was its flexible delivery model and the ability to pay only for resources consumed. As a SaaS (software as a service) provider for content rights management product solutions, Modevity was keen to work with a partner that had a similar approach, as well as provided the flexibility to grow the infrastructure as its user base and global footprint grew.

According to Canova, "To continue to be successful, we have to keep our customer's software fully functional and reliable 24 x 7. Verizon Business understands this, and in fact, Verizon Business delivers CaaS with the exact same approach we use for our customers. We are confident that in Verizon Business we have selected a cloud-computing leader, and that Verizon Business will serve as a true seamless extension of the Modevity team."

Wednesday, June 3, 2009

Verizon Cloud-Based Computing as a Service


Verizon Business introduced an on-demand, cloud-based Computing as a Service (CaaS) solution -- designed to meet the stringent security and performance requirements of their enterprise customers.

This new offering helps businesses take advantage of cloud (IP-based) computing to more efficiently and securely manage IT computing resources -- server, network and storage -- to meet day-to-day business demands.

This CaaS solution, which leverages Verizon's global IP infrastructure and data centers, enables companies to use a Web-based portal to employ computing resources in the quantities and duration dictated by their own business needs.

As a result, businesses pay for the resources used and avoid having to build out for peak capacity requirements by buying new equipment and adding IT or networking staff.

Designed for mid-to-large-sized businesses, CaaS is ideal for new development projects, major events and migrations so that organization can easily and quickly shift IT resources as required.

Just-in-Time Computing Resources
It is also well suited for businesses with seasonal demands such as retailers, companies holding annual benefit enrollments or sales promotions that drive incremental traffic to Web sites. The service is immediately available in the U.S. and Europe, and then will be introduced to the Asia-Pacific region in August.

Verizon's Mike Marcellin explains in a video commentary some of the key features and benefits.

Melanie Posey, research director, hosting & telecom services at IDC said "Verizon has incorporated a number of key elements that make this solution a stand-out in the marketplace. The CaaS combination of flexibility, security, performance and resiliency is well positioned to serve certain enterprise requirements in a nimble, next-generation fashion."

Clearly, we can anticipate that the forward-looking managed and hosted service providers will continue to launch innovative new managed cloud service offerings that meet the selective IT out-tasking needs of their customers.

Wednesday, May 20, 2009

Security and Monitoring of Online Tests

A reader asks about security issues related to giving Twitter-enhanced (or for that matter online) tests:
Do you monitor the student's laptop screens with an application like Altiris Vision to prevent students from using tools that are not allowed on the test? What prevented a student from finding a complete English translation of In Taberna on the web and then uploading bits of "translated" text to the twitter feed and ultimately the blog without ever doing any real translating at all?

Great question.

Low-tech answer: I have students clear the browser cache before starting an exam. Then they open only the 'allowed' sites as tabs in a single browser. I can either do random spot checks where I look at the browser history / recently closed tabs or when the students submit their tests, I could have them submit a screen shot of their browser histories showing the time the test was turned in.

Either method just takes a moment of time.

In terms of pre-loading things to Twitter: I'm following the feed myself and have access to all of their sends. I also do random DM checks to make sure they haven't used that feature to crib notes.

All that said, I really haven't had a problem.

Early in the year I caught a bunch of kids doing something inappropriate online regarding something they had actually put on their blogs. And so, before class one day, I projected the offensive item up on the wall and left the room. By the time I got back a few minutes later, all of the students had come in and were sitting at their desks silently. I pulled the projection and started class.

Never said a word about it again, and haven't had to deal with inappropriate messages on blogs again.

I'm generally against the use of spying software. I tried out SynchronEyes, but quickly found a simple hack around it. Seems like you could throw all the money you wanted to into any of that sort of software and someone will find a hole. Even more importantly, however, I think that sort of software sends the wrong message. I don't want my students to think of me as Big Brother. My classroom is built on trust. Where's the trust in that?

There are plenty of human options for cutting down on cheating. It's really all a matter of how you run your class.

The kids think they know whether they can pull one over on you or not. So in my class, I demonstrate to them all of the ways to pull one over on me. And then I demonstrate to them exactly how I catch those things.

I guess it's a matter of transparency.

Friday, January 23, 2009

Managed Security with a Strategic Twist


Managed services provider Verizon Business has added an interesting twist to its security toolbox. Traditionally, managed security services are tactical: they monitor a network for potential attacks, using virus signatures and other definitions.

Earlier this month, Verizon upgraded its customers' security capabilities with what it calls its "Risk-Correlation Service," designed to add strategic insight to security.

The RCS works with vulnerability scans -- either those it does for customers or those from vendors such as McAfee, Qualys, and others -- to determine where potential vulnerabilities exist. The service also documents your system to create a map of devices and the business processes that run on them. "It marries threat information with vulnerability information," says Jonathan Nguyen-Duy, Director of Product Management for Verizon.

Calculating Risks
The result is a Web-based scorecard that shows Verizon customers not only where potential problems exist, but rank the level of relative importance of those devices. "We can tell you the likelihood of an event on a particular device, but also the business process associated with that device," says Nguyen-Duy. "Using the information from the vulnerability scan, we can tell you about the impact on availability. Is the device running real-time transactions, or is it a database server that might have less sensitive information?"

Strategically, companies can use the information presented in the online scorecard to get a sense of where to improve their online protection. Not all information is created equal, and not every database server requires the same level of protection.

The scorecard is designed to help companies prioritize their security budgets and their business continuity programs. "With limited resources, it's important to understand the relative risk of each vulnerability," he says.

Protection from Attacks
The online scorecard also works when attacks are underway. In those instances, it helps customers work with Verizon to identify where remediation is most important. "Sometimes you have to work in real-time to figure out where attacks are happening," Nguyen-Duy says. "Your ability to respond is improved when you have better information on the threat and what business process might be affected."

Being proactive about security is like flossing your teeth; you know you should do it more often, but it doesn't always happen. Applying a methodology that combines both strategic and tactical security needs is very wise. Clearly, when it comes to security, it's easier to be reactive when you've already been proactive.

Besides, the complexity of providing comprehensive network security protection, and keeping it fully up to date, is something best left to the experts. That's why managed security is one of the most utilized managed service offerings.

Tuesday, October 14, 2008

Online Security in a Global Networked Economy


Because of the expanding growth and complexity of communication networking, and the risks presented by a new breed of skillful hackers, serious security threats are an unfortunate certainty within the highly interconnected office environment of today.

These threats are very real and the results are costly to those businesses that have been affected. Apparently, the victims aren't entirely at random, which is often assumed to be the case.

According to the 2007 CSI Computer Crime and Security Survey, almost one-fifth (18 percent) of those respondents who suffered one or more kinds of security incident further said they had suffered a "targeted attack" -- defined as a malware attack aimed exclusively at their organization or at organizations within a small subset of the general population.

Beyond the Virus Threat
Moreover, financial fraud overtook virus attacks as the source of the greatest financial losses. Virus losses, which had been the leading cause of loss for seven straight years, fell to second place.

In today's global marketplace, every business needs to be vigilant in pro-actively protecting its corporate assets. Gone are the days of simply scanning for viruses. Today a comprehensive, layered approach is required to secure the network and company resources from multiple types of threats.

Small and medium-sized businesses (SMBs) are particularly vulnerable because they typically do not have expert resources on staff to ensure the network is secure, that regulatory compliance issues are being properly addressed, and that network monitoring and updates are effectively maintained 24 hours a day.

Alternative to the In-House Solution
Managed service providers can help SMBs secure their network by deploying a layered approach that uses various advanced technologies and solutions, protecting the network, and anticipating multiple types of potential security breaches -- from Trojan horse attacks and spyware, to data tampering and information theft.

Managed security services create a resilient multilayer defense:
  • Prevention -- proactively keeps the intrusions out
  • Detection -- identifies when an intrusion is occurring or has occurred
  • Response -- takes action to defeat a potential intrusion once detected
The advantage of working with a managed security provider is that services can be scaled to meet an organization's exact security requirements. This flexibility allows companies to minimize service outages and operational expenses, thereby reducing the overall financial impact.

The Challenge to Stay Current
Frankly, a large enterprise IT team can also benefit from an out-tasked network security solution, as the demands to ensure that in-house staff is staying current increases exponentially over time.

Ask a managed service provider to help you assess your security needs and design the best solution for your business. A comprehensive security audit is often the first step in this process.

By all means, be prepared for the unexpected, and keep your business safe. However, this is a complex task that's best left to the experts, while you free-up time to focus on your core business objectives.