- 1
- 2
- < previous
Controlled Airspace
In the future, Frequency Selective Surface panels from the likes of BAE Systems might be able to keep your wireless traffic in-house and wireless intruders out. But until this so-called stealth wallpaper - which blocks specific radio frequencies - becomes commercially available, you'll need to approach wireless security with more mundane techniques.
First off, most Wi-Fi devotees say that CIOs shouldn't fight Wi-Fi. The technology's low cost and simplicity make outright bans impossible to enforce. Therefore, developing a sound strategy to control Wi-Fi's proliferation is all the more critical for CIOs. "We knew wireless was coming. We knew it was a legitimate business need. We knew we had to do something," says Fredricksen. "But out-of-the-box wireless is absolutely contrary to the security controls we have put in place." So Fredricksen went back to the basics. "We applied the same security baselines to the wireless initiative that we apply to all of our other projects," he says.
Alternate Routes
Regarding the denial-of-service flaw, Fredricksen says, "There would always be an alternate way to get the business done," whether users would have to switch to a wired connection or go to an offsite kiosk. But, he concedes, you have to ask yourself one tough question: "If you had a branch become 100 percent wireless, how devastating could [an attack] be?"
To mitigate that scenario, a thorough and well-understood wireless policy is critical. "From the CIO perspective, you have to have the appropriate staff and technology solutions," says Ollie Whitehouse, technical director of @Stake's United Kingdom division. "You also have to have a policy and procedure to back it all up. If not, the first two are useless in the end." That policy should at the very least cover network and device management, as well as monitoring and enforcement mechanisms. CIOs also need to weigh the risks involved with placing your company's most sensitive information up on a Wi-Fi network - for example, consider the health-care, government and financial sectors. If the information is mission-critical to the business or if your company operates in a heavily regulated industry, security becomes even more paramount.
New Management
CIOs need to make certain that attackers cannot get to the hardwired corporate network through a WLAN hole. "You always have to be thinking about how you can narrow the aperture of the target space without hurting your business," says Tim Keanini, CTO of nCircle, a network security vendor. "You have to assume an opponent is actively trying to find your flaws." That means unauthorized access points need to be found and terminated, and authorized access points need to be situated in areas where the radio frequency footprint isn't extending beyond your offices. Default security settings on Wi-Fi-enabled laptops and handhelds need to be cranked up to your company's standard security levels. Those devices also need to be running, at the very least, these security programs: For user authentication, use Media Access Control (MAC) filtering; for Radius authentication and authorization, use Kerberos or smart keys; and for encryption, use Wi-Fi Protected Access (WPA) or virtual private network (VPN). Also, make sure th at ad hoc or peer-to-peer Wi-Fi connections are not permitted on mobile users' laptops.
"The Wi-Fi communications medium can be made secure," says Whitehouse. "You can make the transfer of data through the air secure."
Rigid Enforcement
One of the more crucial steps in ensuring Wi-Fi security is monitoring your company's airwaves. And it's also the one on which most companies trip. For those companies that say "No Wi-Fi", security experts offer a test: Scan your building for Wi-Fi access points using a sniffer tool, and most likely, you'll find some hot spots. "How do you really know [you don't have rogue Wi-Fi users] if you aren't monitoring your systems?" asks Anil Khatod president and CEO of AirDefense, a wireless security vendor. "How do you enforce the policies?" He says that around a third of the companies using AirDefense's wireless monitoring products have a policy of no WLANs; they're simply trying to enforce the policy.
Wireless intrusion detection systems now being offered by a handful of vendors - including AirDefense, AirMagnet, AirWave Wireless and Internet Security Systems - can provide another layer of Wi-Fi security. These systems can detect attackers, rogue access points, unusual network occurrences and, as Whitehouse terms it, allow a certain level of compliance assurance. "This compliance assurance comes from such things as allowing enterprises to detect misconfigured devices that may expose the wired enterprise network to attackers," he says.
So Looi's denial-of-service discovery lingers in the Wi-Fi world, unfixed. But many users claim that they will deal with this problem as they have dealt with other Wi-Fi vulnerabilities - with proven security practices, communication with users and hopefully a bit of luck.
- 1
- 2
- < previous
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
Achieving the impossible: Unlimited application scalability
Strategies for Eliminating .PST Files
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Data grids and service-oriented architecture
Radicati Market Quadrant 2008 on Corporate Web Security
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
- White PaperJoin industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.
- White PaperYour organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.
- White PaperJoin Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00
Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly. - +
Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00
Texas uni announces the Institute for Cyber Security.The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state. - +
Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00
Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions. - +
International Challenges in PCI Security 20 November, 2008 09:15:00
In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective. - +
PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00
Quality assurance plan targets security assessors and scanning vendorsThe PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
Vignette Announces 2008 Excellence Awards 21 November, 2008 10:50:00
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 20 November, 2008 17:34:00
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 20 November, 2008 12:06:00
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 20 November, 2008 12:04:00
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 20 November, 2008 12:02:00
|
||
|
||
|
|
||
|
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Midsize businesses cannot operate effectively without the ability to control access to their networks and business systems. A strong identity management platform can play the role of gatekeeper and guardian of business intelligence and information. Read on to discover how you can create a strong identity management plan to protect your business.














