|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Are firewalls pointless? By Dan Ilett, ZDNet UK April 11, 2005 URL: http://www.zdnet.com.au/insight/security/soa/Are-firewalls-pointless-/0,139023764,139187851,00.htm
The inconvenience of shoring up security infrastructures is restricting the evolution of the extended business. Something needs to change and the UK security user group the Jericho Forum believes it has the answer. The roving gang of European chief information security officers claims the key to better security is less walls not more -- a concept they call de-perimeterisation. De-P is ugly shorthand for the recognition that you can't do business if you hide behind walls. As the city of Jericho found out in the sixth book of Joshua, walls fall down. But if you can't hide, what can you do? Trust and verify. Establish those whom you trust. Verify that they are who they say they are. Make sure they only have access to data they need. Ignore everything else. Security is a process not a product, says Jericho, and an open process at that. Establish open standards for identity management, digital rights, encryption and data-level authentication, and we can eventually do away with the rest of the security infrastructure altogether while maintaining commercial and operational flexibility. This will take a while. But because the Jericho Forum is user-led, it is honest about the problems and pragmatic about a gradual introduction of these ideas. ZDNet UK  spoke to Paul Simmonds, one of Jericho's founders and global information security director of chemical giant ICI, about the ideas behind de-perimeterisation and pushing the organisation's unique take on security to the United States.
Q: What makes Jericho different from other security groups?
And what exactly is the problem, as you see it?
Continued ... (continued from previous page)The big problem is how we are going to operate our businesses in one, two or three years' time. It's a about being able to operate your entire business on the Internet. In reality, you'd be daft to do that -- it would be a [subsection] of that, but that's the pure idea.
Do you really see businesses like ICI and those of other Jericho members such as BP becoming deperimeterised any time soon?
I think we'll start in two years. That's a feasible option. BP -- in terms of changing entire infrastructures, it's a good few years away. And we'll need serious business justifications for it -- and rightly so.
What do you think the outcome of all this will be?
What are you looking for in products exactly?
How does that compare with security technology now?
Why is it difficult to inform people about deperimeterisation?
What challenges have you come across?
UPS and Walmart are championing the AS2 protocol. That's about to go to the IETF for ratification. That allows you to do business to business. It allows us to connect our e-commerce system to someone else's using the Internet. If you can drop your borders you can do an awful lot more of these transactions.
How do you keep a balance between your role in ICI and your commitment to Jericho?
When will you allow vendors to take part in the Jericho Forum?
What do members get out of Jericho?
ZDNet UK's Dan Ilett reported from London. For more coverage on ZDNet UK Insight, click here.
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |