Friday | 16 May, 2008
CIO

Features

Enterprise 2.0 - What is it good for?
A 12-step guide to getting the most out of Web 2.0 tools and making it safe-for-purpose
Sue Bushell 06 May, 2008 16:00:22

7.Beware the Stealth Attack and Stay Alert to Operational Risk

CIOs also need a better understanding of which social networking sites are relatively safe and which potentially dangerous. Late last year Facebook admitted its Beacon ad service was far stealthier than previously acknowledged.

The controversial ad system was tracking users' off-Facebook activities even when they were logged off from the social-networking site, and even where those users had previously rejected offers to have their activities on specific external sites broadcast to their Facebook friends. While Facebook insisted it was deleting the data transmitted back to its servers, the claim sparked outrage and forced the modification of Beacon. Even so, analysts warn the proliferation of social networking services suggests such privacy violations are likely to continue.

Sultan says other privacy issues include the danger of personal information being on-sold to the new owners of an application, and employees uploading their entire Outlook address book to a social networking site. "There is a huge danger of the 'corporate common man' or 'corporate common woman' inadvertently exposing their employer to risk," he says.

"A lot of this is completely uncharted territory and you've got a lot of legality issues. The CIO needs to look at it from a policy perspective.

"Fifty per cent of companies in the US ban Facebook at work. You need to remember that there is a multitude of different devices that people will be accessing information on from work and you really can't be a Nazi about it. At the same time, you're going to have to try to address work efficiency, and keep the peace between multiple groups of people from completely different generations.

"So there's that kind of social and policy concern. There is also the technological concern of what are these applications doing? Are they scraping information? Are they being loaded onto desktops?"

Even so, Joyent 's Boothby sees little risk of blogs or wikis opening up holes in the firewall, since most such technology internally is controlled in the data centre. But he warns there is a risk for the CIO from an operational perspective.

The open Internet is about general communication, whereas behind the firewall, inside an organization it's about operational efficiency. The tools that were designed for open freewheeling communication are not necessarily the best tools to help you deliver operational efficiency behind the firewall, he warns. So while a wiki may be a good thing outside the firewall, it may not have sufficient structure to be successful behind the firewall.

"My opinion is that when CIOs are setting up and starting to use some of these things it's best to experiment in the small group, it's best to run it on the flexible infrastructure, and it's also best to think about things that actually have enough structure to solve specific problems."

"I think for true Enterprise 2.0 stuff, it will still take a little while before they are as prevalent as Excel, but that doesn't mean that companies can't successfully start to benefit from them very quickly," Boothby says.

8.Know That Mashups'll Mess You Up

Beware the mashup - Web applications that combine data from more than one source into a single integrated tool, described by The New York Times as being "at the heart of a generation of Lego-style software that is emblematic of the second generation of the Internet".

While mashups may be growing in popularity, they have major security problems, warns Rick Welykochy, director of Australian company Praxis Services, who says the phenomenon reminds him of the notion of millions of monkeys typing on keyboards in an attempt to produce something legible. Plug-in and drag 'n' drop programming is not new, Welykochy points out. It is simply new to the Web. But often component "glue" in the form of programming "fu" (nous) is required to make components interact with each other correctly.

"I once watched someone drag 'n' drop a 'browser component' into a Delphi workspace windows. Voila! A new Web browser to take on the likes of Netscape and Internet Explorer. Not. A weak piece of componentry that was totally inadequate for its intended job.

"Methinks this is yet another novelty aimed at the me-too gadgetry generation that will have minimal if any use in the enterprise. Hey, but then again, the CEO of IBM predicted the need for only five or six computers worldwide back in the 1940s. So I could be wrong," Welykochy says.

Market Place
 

2008 CIO Summit

19th August, 2008 Four Seasons Hotel, Sydney Developed in partnership with CIO Magazine, IDC, INTEP and the CIO Executive Council.

The world of the CIO is extremely complex and diverse. Multiple priorities demand attention and decisions are needed instantly. Individual teams need to be driven towards common goals, and businesses strive to become more mobile, agile and responsive. For CIOs, the challenge never ends.

Every year the CIO Summit identifies what is top of mind for CIOs across Australia and New Zealand, and offers insight for CIO benchmarking and vendor strategic planning alike.

Recent IDC research shows that over 59% of CIO's believe that 'to achieve their business strategies, technology should be used more aggressively than today.'

Join us on August 19th to discover how this is possible with the latest technologies including Virtualisation, Web 2.0, IP Surveillance and Software as a Service (Saas).

Click here for registration.

Please email Denyse_Robertson@idg.com.au for further information.

  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Phishing botnet expands by hacking legit sites 15 May, 2008 08:10:59

    Plants SQL injection attack tool on bots, hacks business, education sites
    A botnet is now using a SQL-injection attack tool designed to hack legitimate Web sites, a move meant to add more hijacked PCs to its collection, according to a security researcher.
  • +

    Which IT security skills are most important? 14 May, 2008 09:21:43

    There are two types of security skills that might be needed in a company: tactical security operations and strategic risk management.
    I often hear from IT executives that it is hard to recruit and retain "good security people." Many lament the shortage of skills in this area and cannot reconcile the skills offered with the positions that need to be filled. Is there really a shortage of good security people? Or just a mismatch in the skills and the jobs?
  • +

    Icy encryption tool protects laptops from "cold boot" attack, vendor says 14 May, 2008 08:36:43

    Vulnerable encryption keys erased by HyBlue's IceLock
    The vendor HyBlue says it can prevent the "cold boot" encryption hack discovered by Princeton researchers with a laptop security product announced Tuesday.
  • +

    Great Wall of Australia: Industry cops sanitised Internet 14 May, 2008 16:45:04

    Content filtering gets budget go-ahead
    Communications Minister Stephen Conroy has pushed ahead with the controversial [[artid:420013177|national content filtering scheme|ISP filtering]] with a $125.8 million budget allocation announced today.
  • +

    Hacker writes rootkit for Cisco's routers 15 May, 2008 07:07:51

    A hacker has written rootkit software that works on Cisco's routers.
    A security researcher has developed malicious rootkit software for Cisco Systems' routers, a development that has placed increasing scrutiny on the routers that carry the majority of the Internet's traffic.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

The State of Internet Security

Email security threats are having a significant impact on businesses worldwide. Discover the most critical email security-related concerns, and get expert advice, current industry data, trends and learn the essential steps to protect your corporate email.

Sponsored Links