Please wait while the page is being loaded Skip this advertisement >
Friday | 5 December, 2008
CIO
The Service Way to Security
One of government's biggest challenges is to transition from a general awareness of cyber security to concrete implementation of good cyber security practices.
Sue Bushell 29 August, 2006 12:31:38

Ronald Reagan once famously said: "The nine most terrifying words in the English language are, 'I'm from the government and I'm here to help.'"

Inside the government itself, the most terrifying words in the English language may be: "The information security office is here to facilitate your office's goals and objectives."

So says a new book, Larstan's The Black Book on Government Security (publication date October 2006), intended to introduce managers and IS professionals to the key cyber security challenges faced by all levels of government.

The book notes that while awareness of the importance of cyber security is growing at all levels of government, awareness is one thing; action another. One of government's biggest challenges is to transition from a general awareness of cyber security to concrete implementation of good cyber security practices. Ensuring cyber security issues are championed by leadership, embraced by business managers, implemented by users and understood by all is like herding cats, it says, especially when cyber threats are very difficult to understand.

"A cyber attack is so amorphous it is often difficult to grasp the concept. It's nearly impossible to determine where a cyber attack will come from, who will launch it, the exact target and the nature and extent of the payload," the book says. "This uncertainty is fostering an accelerating loss of trust in the systems we have relied on for years."

Here a service-oriented architecture (SOA) has a major role to play. There have been significant demands on government to share information in the wake of 9/11, notes co-author Paul Patrick, vice president and chief architect AquaLogic, BEA Systems.

These demands create huge issues across governments, and even within some government agencies. The US Department of Homeland Security (DHS), for example, is a composite of 17 agencies rolled into one and now charged with acting like a single entity. While information sharing issues may not be as obvious - nor as pressing - in other agencies or governments, they nonetheless exist.

"In fact, there has really been a culture shift in government agencies and IT always reflects the culture of a given organization. In the past, government agencies were acculturated NOT to share, so IT was built in silos; proprietary apps and codes built barriers against information sharing," Patrick says.

"Now that information sharing is mandated, governments have to look at how to tie systems together. Obviously, this is huge integration issue, and this is where a service-based approach comes in. To facilitate info sharing, an organization can create an SOA, a collaborative system for linking resources on demand, with a common infrastructure based on open standards. SOA integrates functions to provide actionable data.

"In terms of security, in the past, security was built into individual, often proprietary apps. It was as if each agency thought it was the center of the world. Now that agencies realize that is definitely NOT the case, how do they facilitate sharing-becoming a community of interest-while at the same time creating a safe and consistent. In order to do this, you need to get security out of the individual application codes, and instead attach it to the metadata in the infrastructure. In other words, security needs to be abstracted away form the apps."

The US government - the world's largest IT enterprise - is moving full tilt ahead toward creating a service-based environment, Patrick notes. And the Australian government, with the recent completion of two major projects, is also moving quickly into service-based territory.

More about BEA, BEA Systems
Featured Whitepaper Sponsors
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    SOA What? Why You Need SOA Governance Framework 04 December, 2008 08:32:00

    Adopting services oriented architecture (SOA) in your enterprise without thinking through IT governance can cause something like the Gold Rush in the 1800s; extreme rates of growth and minimal law and order which produce unexpected outcomes.
  • +

    The Myth of Cloud Computing 04 December, 2008 08:25:00

    Why the rapid spread of virtual technology is becoming a security risk
    Why the rapid spread of virtual technology is becoming a security risk.
  • +

    Who Pushed Vendors Toward Better Security? 04 December, 2008 09:38:00

    Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson
    Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson.
  • +

    CPO & CISO: A Comprehensive Approach to Information 04 December, 2008 08:42:00

    GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.
    GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.
  • +

    Security Culture: Americans are Ferengis, Europeans are Vulcans 04 December, 2008 08:32:00

    Lunch table conversations tell a lot about the culture of security in Europe and the US
    Lunch table conversations tell a lot about the culture of security in Europe and the US.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Discover the advantages of an open architecture multi-vendor network solution

View this webcast and discover the drivers for changing network design practices, why many organisations are changing their approach to network architecture and how enterprises should be moving forward with open architecture multi-vendor network solutions. Register now and learn how your business can maximize the business value of the enterprise network.