We're All Outside the Wall
by Peter Coffee on September 7, 2007 at 01:05 PM
Forrester Research has made it official: the "walled city" model of enterprise network security is as out of date as the medieval fortress. Forget perimeter defense. What's needed, going forward, is a far more intelligent and focused approach -- one that's more like snipers confronting attackers one-on-one than like massive and costly barriers, readily shattered by the cost-effective trebuchets of automated attack.
Going forward, it's clear that outsourcing security is no longer a speculative idea or a low-budget approach. Rather, it's a question of putting the expertise in the same space as the problem. Security in the cloud is more likely to be a professional service, managed by people whose entire business model depends on unimpeachable credibility in that space. I explored this question this past February in an eWEEK podcast, still on line if you'd rather listen than read. (My wife and my oldest son never got the credits they deserve for my weekly series of eWEEK InfraSpectrum programs: she did the voice-over intro, he wrote and digitally performed the intro and closing music.)
Security for ever-enriched Web-based offerings is therefore a top-tier concern, not just for consumer-facing applications but also for enterprise IT. This concern got some high-profile attention at the Black Hat conference in Las Vegas this summer, with one researcher raising red flags here at salesforce.com by innocently using our service as an hypothetical example of a "sidejacking" target: upon further review of salesforce.com security technologies and administrative options, that same expert quickly clarified his comments with a blog post that dubbed salesforce.com "the standard that others should follow."
We can only hope that the future of security will look more like armored vests for the marketplace than like easily penetrated or shattered walls.
TrackBack
TrackBack URL for this entry: http://www.typepad.com/services/trackback/6a00d8341cded353ef00e54ed96b658833
Listed below are links to weblogs that reference We're All Outside the Wall:


Comments
Posted by JKalishman on November 20, 2007 08:45 AM:
I read your blog entry with great interest because our company has created the first on-demand security product for protecting on-demand application data. With more and more services operating outside of the firewall, we've attacked the security threat in a new way to prevent theft of downloaded data. Simply put, we stop downloaded data from being removed from the authorized user's PC without the knowledge or authorization of the company. So, for those companies that use Salesforce, they have access to the first solution that protects on-demand data from theft and it's integrated directly into their Saleforce account.