120 likes | 228 Views
The State of Network Security 2012: Attitudes and Opinions. Introduction. The network environment continues to grow in complexity as firewall policies expand over time and as new technologies such as next-generation firewalls are adopted.
E N D
Introduction • The network environment continues to grow in complexity as firewall policies expand over time and as new technologies such as next-generation firewalls are adopted. • This survey analyzes network security risks and operational challenges of managing network security policies. Additionally, it gauges the effect of next-generation firewalls on IT’s workload.
Methodology • This survey was conducted at RSA 2012. • 182 respondents are deeply involved in their organization’s IT function and have at least a moderate involvement in network operations. • 68 percent are Information Security professionals. • 32 percent are Network Operations professionals. • No AlgoSec employees, customers or partners are counted in the results.
Key Findings Network security processes need improvement. • From reducing system outages to improving business efficiency. Next-generation firewalls address threats - at a cost. • Improved security, but increased administrative workload. Security is an inside job. • Visibility of applications and networks, improving processes and defending against insider threats all rank as key concerns.
Network Security Challenges • The majority (55.6%) of top challenges lie with problematic internal processes.
Out-of-Process Changes Cause Major Problems • 77% of respondents noted that out-of-process changes caused either a system outage, a data breach an audit failure or more than one of these.
Next-Generation Firewalls: Better Security… • 84% of respondents said NGFWs provided them with better security BUT…
Next-Generation Firewalls: … at a Cost • 76% of respondents said that NGFWs increased their administrative burden due to added policy complexity
Greatest Risk? More Management than Malice • External attackers are well down the list of concerns… • The greatest risks noted are poor internal security management processes and insider threats
Key Recommendations • Clearly define internal processes, ensure they are communicated to all stakeholders and above all else, make sure they are enforceable. • Leverage automation to facilitate process improvement and to improve business efficiency and agility. • Look to implement NGFWs, but understand the impact of policy decisions and plan accordingly to gain the security benefits without the cost of higher administrative burden.
Educational Resources • Here are additional resources to help you further research automating network security policy optimization and change management: • Webinar: 5 Strategies to Improve Firewall Management • eBook: The Big Collection of Firewall Management Tips • Video Testimonial: BT • Free 30 Day Trial of AlgoSec Security Management Suite
Security Management. Made Smarter. www.AlgoSec.com Connect with AlgoSec on: