Leave Security to Insiders

執筆者
Craig Stinson
Craig Stinson
Published: Aug 13, 2001
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Protecting networks from outside attack is far too important to just run “by the numbers.” Although a lot of discussion about firewall and VPN appliances involves performance numbers—and these are critical—IT managers should be even more concerned with how quickly firewall rules and alerts can be managed.

Furthermore, IT managers should turn their backs on any notion of security as a “service” for the same reason. Based on eWeek Labs testing, it is clear that high-end security appliances are too powerful to be placed in the hands of someone who wont suffer immediate and dire consequences if something goes wrong.

The confusion about threats and the fact that good security policies require an intimate knowledge of IT weaknesses are also good reasons for organizations to keep their security management in-house.

Finally, as we discovered, once again, in our examination of two high-end firewall/virtual private network appliances, Nokia Corp.s IP740 and SonicWall Inc.s GX650, creating effective access rules demands an intimate knowledge of how your organization works.

It isnt enough to put a service-level agreement in place and then proceed with monthly throughput and blocked-attack reports. Security appliances by their nature are throttles on network performance that must be adjusted to get the right balance between security and openness.

We were impressed with the Nokia IP740s ability to use Check Point Firewall-1 to push out access rules and security policies to test devices from a central location. We were able to write a rule once and easily distribute it to all the devices in our test network. In the real world, being able to deliver up-to-date rule sets that provide real protection for the network is just as important as the speed with which those rules process information.

Generically written access rules, the kind that are likely to come from a consultant, are easily made redundant or, worse, nullified by subsequent rules. This erodes productivity. Efficient, effective rules require an insiders knowledge of the organization.

This isnt to say that there isnt room for security consultants while planning and implementing a firewall/VPN rollout. In fact, outsiders are especially good at initially evaluating IT weaknesses and making recommendations to patch the most obvious holes.

Advertisement

However, IT managers should be leery of using outsiders to control access to the information and systems that are the basis for businesses, whether made of “e” or clay.

Craig Stinson

Craig Stinson is an editor of PC Magazine. Stinson writes about decision-support, personal productivity, reference, and educational software. He is the author or coauthor of more than fifteen books on Windows and Excel, including The Windows 2000 Expert Companion and Excel Version 2002 Inside Out (both from Microsoft Press).

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。