home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers




Your Network's Not Ready for E-Commerce

By Brian Walsh  A first-time e-commerce project manager informs management that after due diligence, package selection and integration, enabling the company's Web site for e-commerce will take six months and cost approximately $400,000. He then notes that the only thing left to do is to inform the network group. But what can the network group really add to the project, he wonders? Maybe a new T1 line? Well, he has already budgeted for that, to the tune of $1,000 per month and 30-days' notice to install. All in all, he anticipates no problems.

The lies we tell others are bad, but it's the lies we tell ourselves that really get us into trouble. The reality is that security is hopelessly lacking on internal segments behind the firewall, which could cause our project manager's figures to grow by half, or even double, by the time the project is completed.

Introducing e-commerce to an organization exposes quite a few of these little lies. You've heard them: "Our firewall protects us from the Internet." "Since the Web server is in the DMZ (demilitarized zone), we don't have to worry about it." "Our internal systems are secure." "We don't have anything worth hacking." "Security is a network problem." And my favorite, "Our production systems are flexible because they're based on standards." What a panic! It actually would be funny if not for the time and money involved.

These lies contribute to the security rationalization concerning network deployment behind the firewall. The architecture of internal segments is driven by several factors: historical accident (we needed it, we added it), performance (based on user complaints, we moved the servers to their own segment) and/or reliability (someone will get fired if there's a problem with this application, so we'll buy two of everything). Rarely has security been the driving factor in the tactics of network architecture and, consequently, the firewall is often the only secure part of your network. E-commerce just happens to be the first application to demand the same degree of security behind the firewall as is traditionally applied to the DMZ.

Making Myths Web server host security is enough for e-commerce, right? Wrong. Although Web application folks and project managers often believe this myth, the truth is that no matter what security scheme you've employed to protect your Web content, it won't be good enough for e-commerce. However, those of us in the networking space must also shoulder some blame. See, the project manager remembered what you said in passing last year, "Our Web server is secure." And, of course, the project manager then assumed that your statement applied to any Internet application. You then supported that implication by not explicitly stating, "But our internal systems A through Z are not secured."

Essentially, the problem is that the e-commerce initiative everyone in IT is so jazzed about will touch practically every application and database in your shop. Gone is the luxury of defending only a single segment. That innocent Web server will start opening sessions to servers on all of your production segments. Take heed: Do not respond to this challenge by questioning, "Well, can't we just duplicate all that data onto servers on the DMZ?"

Until now, your firewall has served as "a hard crunchy shell around a soft chewy center." (Thank you Bill Cheswick, Bell Labs, Lucent Technologies, for the imagery.) I know, I know--administrators look after all the servers, and you've distributed a security policy to all your personnel. However, if the thought of a server on your DMZ opening a session with a server on an interior segment fills you with dread (because once hackers have access to the production segment they can traverse all segments at will), how do you define usable, flexible security? E-commerce is more than just selling online; it gives your customers and partners access to some of your core data and applications.


Related Links

Inside Outsourcing
August 1, 1998

The 'Q' In QoS Stands For Quality
September 1, 1998

Building a Business Plan for an E-commerce Project
September 15, 1998

Is 'Good Certification Program' an Oxymoron?
October 1, 1998

The Once and Future Development Standard
November 1, 1998


Other Columnists

Top of the Stack
By David Willis
On the Edge
By Art Wittmann

Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page


e-mail E-mail this URL






Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights