|
Vendor Accent
A blueprint for managing the Windows environment
The release of Windows Vista is an opportune time for IT
departments to assess whether they are doing all they can to provide the most
complete protection available against risks to security, availability, performance,
and compliance By Anil Chakravarthy
As
todays enterprises know all too well, the complexity and cost of managing
Microsoft Windows environments continue to increase. Complicating matters further
is the fact that IT staff and resources at most enterprises are limited. The
result: Each day, IT departments must struggle to achieve the right balance
between satisfying demands for information and ensuring that information is
secure and available.
With the recent release of the Windows Vista client operating system, it is
an opportune time for IT departments to assess whether they are doing all they
can to provide the most complete protection available against risks to security,
availability, performance, and compliance. This article offers a blueprint for
protecting against those risks.
Windows Vista is not a security solution
For
enterprises considering the impact of the Windows Vista operating system on
their computing environment, there are several basic issues to address. First
and foremost, Windows Vista is not a security solution in itself. Microsoft
is taking care of the basics by improving the security of its newest operating
system, but it is not positioned to address the broader needs of the market.
(For example, Windows Vista does not include virus protection.) Simply put,
Vista does not provide the full protection that enterprises need.
Why is that? Partly its because the nature of the threats to the Windows
environment has changed. Large Internet worms targeting thousands of users have
given way to smaller, more targeted attacks focusing on fraud, data theft, and
other criminal activities. The days of Web site defacements and low-level information
gathering attacks are long gone. Today enterprises are more likely to see encrypted
bot networks, remotely initiated database breaches, sophisticated phishing scams,
and customised malicious code targeting specific companies.
Moreover, todays blended threats attack multiple vectors, looking to exploit
any means possible to gain access to sensitive information. To combat these
new threats, enterprises need multiple layers of protection at the gateway,
server, and desktop levels.
At the same time, enterprises face increasing challenges in managing their information
systems in todays always-on, connected world. Theres intense competitive
pressure to provide greater access to information and applications across a
growing network of partners, remote employees, and customers. Accomplishing
that mission, while continuing to meet business objectives, gets harder every
day.
Complete Windows protection
To address these challenges, enterprises require a range of solutions that help
them effectively and affordably secure their business data, maximise
the availability of their systems, protect their key applications, and set and
enforce IT policies.
Growing data volumes
Data volumes continue to grow at 40 to 60 percent each year, according to IDC,
making it more difficult for administrators to back up mission-critical data
in acceptable time frames (or within available backup windows). In addition,
the need for instant, on-demand data recovery is becoming increasingly vital
for business operations. Data security and availability solutions help provide
continuous data protection, secure data access, and rapid data recovery. Disk-based
data protection, specifically continuous data protection, addresses these issues
in a way that eliminates the need for backup windows, allows end users to recover
their own data without contacting IT, and delivers an integrated disk-to-disk-to-tape
solution.
Securing systems
With enterprises having to protect a growing number of mobile users, branch
offices, and online transactions, the challenge of managing PCs and servers
has become much more complicated. Operating system and hardware upgrades, new
security vulnerabilities, and the need to deliver software updates to users
across the network make the challenge even more time-consuming and costly. Moreover,
system recovery is a long, error-prone task that can leave mission-critical
servers offline. System security and availability solutions deliver simplified
system administration and protection, providing everything a business needs
to help it stay up and running at all times.
Applications
E-mail has become a mission-critical application and a primary channel for business
communications and transactions. Its also a key repository of information
and records. As a result, the slightest downtime can disrupt business and even
have legal implications. Unfortunately, there are many threats to maintaining
messaging system uptime. Spam, worms, and phishing attacks are driving up message
volume and exposing Windows-based messaging systems to greater risk of downtime.
Application security and availability solutions include security, archiving,
storage, and backup products to help ensure the protection and accessibility
of e-mail, information, and applications.
Implementing policy
Protecting business systems means implementing effective IT policies. And in
many cases, having strong policies isnt just a smart optionits
a legal obligation. Governance rules and regulations such as the Sarbanes-Oxley
Act and the Health Insurance Portability and Accountability Act dictate tough
standards for data protection, retention, and privacy. However, setting, enforcing,
and reporting on compliance policies can be complicated and costlyunless
the right tools are in place.
Policy management solutions streamline and automate the creation and enforcement
of effective IT policies and compliance procedures that address government regulations
and industry standards for data protection.
Today, ensuring the highest level of protection across Windows environments
requires a combination of leading technologies and services. That message is
especially pertinent now that enterprises are beginning to put Windows Vista
through its paces. Enterprises that wish to proactively address the increasingly
complex challenges facing IT would do well to adopt a comprehensive blueprint
for protecting data, systems, and applications and enforcing IT policies.
The author is Vice President, India Technical Operations,
Symantec Corporation anil_chakravarthy@symantec.com
|