2001ABA banking journalRequires access

Managing Information Security Risk 2001

Peter S. Tippett, David T. O'Neill

Open publisher page 22 citations

Abstract

Internet security: it's just not working It's an unfortunate fact that information security at most organizations today is unequal to the threats to critical data and systems. One only need to look at the headlines: the list of companies that have suffered potentially devastating security breaches in the past six months includes some of the largest, most successful, and technologically astute organizations. These are companies with the right security products, competent in-house security staff, and a compelling business need for good information security. How can this be? It's simple-security in the Internet economy has become too complex and dynamic for most companies to deal with, and traditional approaches to security aren't helping. A handful of products and an occasional audit can't address a fast-changing security environment and provide the protection that organizations need. The advantages of cost, speed, and access demand that companies leverage the Internet and open their networks to partners, customers, suppliers (and sometimes even competitors). In this interconnected environment, new and unfamiliar security risks are a daily reality. Six key trends in internet security: 1. Increasing complexity = increasing vulnerability. The more complex a system gets, the more vulnerable it becomes to attack. Vulnerability increases exponentially as complexity increases. The Internet is enormously complex, with operating systems, applications and gateways driven by tens of millions of lines of code. Every day dozens of new vulnerabilities are posted to legitimate and underground web sites. Many pose little risk, but some are quite significant and have led to embarrassing data loss and web site vandalism. These posted vulnerabilities represent only a small fraction of the potential vulnerabilities that lurk within a mosaic of such hugely complex components. While many issues have been addressed, many more lay undiscovered, more than could ever be addressed by an army of quality assurance specialists. 2. Changing environment = new risks. Change means new partners, customers, and employees to an organization. At the technology level, change brings new applications, operating systems, protocols, and hardware. In the security arena, every day brings new viruses, attack tools, and vulnerabilities. Constant, pervasive change requires organizations to assess new risks and develop dynamic approaches to dealing with them. Security must be daily hygiene, not an annual check-up. 3. Greater connectivity = greater exposure. We've moved from a mainframe environment, where critical data was in a locked room, to a Napster era where desktops share information. This random connectivity between networks and devices multiplies the risk of malicious code, hacking, and other threats. New wireless and peer-to-peer technologies promise to take connectivity (and risks) to new levels. 4. Growth in Internet users = growth in Internet abusers. Internet use continues to increase dramatically, making it the fastest growing medium in history. The number of Internet abusers is growing proportionately. For them, the Internet is a tool for mischief, larceny and espionage. Employees and contractors with Internet access from within your firewall makes internal abuse a significant concern. 5. Anonymity fosters abuse. The anonymity of the Internet tempts many to commit destructive or illegal acts that they might not have otherwise. On one hand, new and more effective authentication technologies will eventually make anonymous Internet usage more difficult; on the other hand, emerging privacy standards and regulations may ensure some degree of continued anonymity. 6. Democratization of the Internet empowers abusers. The Internet and related technology have revolutionized industries by bringing access, power, and control to millions. …

About this research paper

What this paper is about

Internet security: it's just not working It's an unfortunate fact that information security at most organizations today is unequal to the threats to critical data and systems. One only need to look at the headlines: the list of companies that have suffered potentially devastating security breaches in the past six months includes some of the largest, most successful, and technologically astute organizations. These are companies with the right security products, competent in-house security staff, and a compelling business need for good information security. How can this be? It's simple-security in the Internet economy has become too complex and dynamic for most companies to deal with, and traditional approaches to security aren't helping. A handful of products and an occasional audit can't address a fast-changing security environment and provide the protection that organizations need. The advantages of cost, speed, and access demand that companies leverage the Internet and open their networks to partners, customers, suppliers (and sometimes even competitors). In this interconnected environment, new and unfamiliar security risks are a daily reality. Six key trends in internet security: 1. Increasing complexity = increasing vulnerability. The more complex a system gets, the more vulnerable it becomes to attack. Vulnerability increases exponentially as complexity increases. The Internet is enormously complex, with operating systems, applications and gateways driven by tens of millions of lines of code. Every day dozens of new vulnerabilities are posted to legitimate and underground web sites. Many pose little risk, but some are quite significant and have led to embarrassing data loss and web site vandalism. These posted vulnerabilities represent only a small fraction of the potential vulnerabilities that lurk within a mosaic of such hugely complex components. While many issues have been addressed, many more lay undiscovered, more than could ever be addressed by an army of quality assurance specialists. 2. Changing environment = new risks. Change means new partners, customers, and employees to an organization. At the technology level, change brings new applications, operating systems, protocols, and hardware. In the security arena, every day brings new viruses, attack tools, and vulnerabilities. Constant, pervasive change requires organizations to assess new risks and develop dynamic approaches to dealing with them. Security must be daily hygiene, not an annual check-up. 3. Greater connectivity = greater exposure. We've moved from a mainframe environment, where critical data was in a locked room, to a Napster era where desktops share information. This random connectivity between networks and devices multiplies the risk of malicious code, hacking, and other threats. New wireless and peer-to-peer technologies promise to take connectivity (and risks) to new levels. 4. Growth in Internet users = growth in Internet abusers. Internet use continues to increase dramatically, making it the fastest growing medium in history. The number of Internet abusers is growing proportionately. For them, the Internet is a tool for mischief, larceny and espionage. Employees and contractors with Internet access from within your firewall makes internal abuse a significant concern. 5. Anonymity fosters abuse. The anonymity of the Internet tempts many to commit destructive or illegal acts that they might not have otherwise. On one hand, new and more effective authentication technologies will eventually make anonymous Internet usage more difficult; on the other hand, emerging privacy standards and regulations may ensure some degree of continued anonymity. 6. Democratization of the Internet empowers abusers. The Internet and related technology have revolutionized industries by bringing access, power, and control to millions. …

Why it matters

OpenAlex reports 22 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Internet security: it's just not working It's an unfortunate fact that information security at most organizations today is unequal to the threats to critical data and systems. One only need to look at the headlines: the list of companies that have suffered potentially devastating security breaches in the past six months includes some of the largest, most successful, and technologically astute organizations. These are companies with the right security products, competent in-house security staff, and a compelling business need for good information security. How can this be? It's simple-security in the Internet economy has become too complex and dynamic for most companies to deal with, and traditional approaches to security aren't helping. A handful of products and an occasional audit can't address a fast-changing security environment and provide the protection that organizations need. The advantages of cost, speed, and access demand that companies leverage the Internet and open their networks to partners, customers, suppliers (and sometimes even competitors). In this interconnected environment, new and unfamiliar security risks are a daily reality. Six key trends in internet security: 1. Increasing complexity = increasing vulnerability. The more complex a system gets, the more vulnerable it becomes to attack. Vulnerability increases exponentially as complexity increases. The Internet is enormously complex, with operating systems, applications and gateways driven by tens of millions of lines of code. Every day dozens of new vulnerabilities are posted to legitimate and underground web sites. Many pose little risk, but some are quite significant and have led to embarrassing data loss and web site vandalism. These posted vulnerabilities represent only a small fraction of the potential vulnerabilities that lurk within a mosaic of such hugely complex components. While many issues have been addressed, many more lay undiscovered, more than could ever be addressed by an army of quality assurance specialists. 2. Changing environment = new risks. Change means new partners, customers, and employees to an organization. At the technology level, change brings new applications, operating systems, protocols, and hardware. In the security arena, every day brings new viruses, attack tools, and vulnerabilities. Constant, pervasive change requires organizations to assess new risks and develop dynamic approaches to dealing with them. Security must be daily hygiene, not an annual check-up. 3. Greater connectivity = greater exposure. We've moved from a mainframe environment, where critical data was in a locked room, to a Napster era where desktops share information. This random connectivity between networks and devices multiplies the risk of malicious code, hacking, and other threats. New wireless and peer-to-peer technologies promise to take connectivity (and risks) to new levels. 4. Growth in Internet users = growth in Internet abusers. Internet use continues to increase dramatically, making it the fastest growing medium in history. The number of Internet abusers is growing proportionately. For them, the Internet is a tool for mischief, larceny and espionage. Employees and contractors with Internet access from within your firewall makes internal abuse a significant concern. 5. Anonymity fosters abuse. The anonymity of the Internet tempts many to commit destructive or illegal acts that they might not have otherwise. On one hand, new and more effective authentication technologies will eventually make anonymous Internet usage more difficult; on the other hand, emerging privacy standards and regulations may ensure some degree of continued anonymity. 6. Democratization of the Internet empowers abusers. The Internet and related technology have revolutionized industries by bringing access, power, and control to millions. …

Key concepts: Business, Computer security, The Internet, Security through obscurity, Vulnerability (computing), Security information and event management, Information security, Security service

Related papers

Back to paper searchBrowse research topicsOriginal source
Managing Information Security Risk 2001 — Research Paper | ScholarLens