India's leading Information Risk Management (IRM) company
  About CII SecureSynergy: ISO27001 certified company          
 
IRM HOME
   
Introduction
Services
  - Consulting
  - Training
Newsletter
News
Security Library
InfoSec Glossary
Contact / Feedback
   
 
AUDIT FACILITATION
Vet an Indian company
 
 
END-USER CERTIFICATION
Certified Information Security Aware User (CISAU)
 
 
CII HOME
Other CII Services
:: WTO
:: TQM
:: TPM
:: Technology & IPR
:: SME
:: Skills Initiative
:: Library
:: IRM
:: Invest India Services
:: Green Business
:: Exports
:: Environment Mgmt
:: Energy
:: Corporate Advisory
:: Climate Change
:: Business Development Services
 
 
 
 
 
 
The single largest factor for Security Breaches
Felix Mohan, CEO - SecureSynergy
 

Malicious code has emerged as the single largest factor for security breaches. According to the CSI/FBI Survey 2002 more than 94% of the large corporations have had sizeable downtime and financial losses due to malicious code attacks. As per the CII-PwC Survey 2002, in India 75% of the corporates have had serious incidences of malicious code attacks "forcing them to shut down external connections to the Internet, resulting in large losses due to downtime and lost business opportunities".

The recent SQLSlammer attack underlines the fact that businesses are not taking adequate measures to fortify their IT Infrastructures. Even those corporates that have implemented the latest anti-virus protection suffer attacks - raising a fundamental doubt about the ability of available anti-virus products to provide the requisite protection.

It is important to realize that an anti-virus software is only as effective as the last update. Today, the speed of malicious code proliferation across the Internet is mind-boggling. In 1990 the Form virus took a year to spread across the Internet, in 1995 the Concept Macro virus took 2 months, in 1999 Love Bug took 9 hours, in 2001 Code Red took 2 hours, and Nimda took a mere 30 minutes to spread. This narrow window has already paled in comparision to the 10 minutes it took SQLSlammer to spread across the Internet in Jan 2003.

What this effectively means is that today there is no longer any window for receiving anti-virus updates. The update has to be done in 'real time'. This is where conventional anti-virus software fail. For instance, Norton provides the 'Liveupdate' facility. Despite the name, this facility only updates your system on a weekly basis - every Wednesday, and when there is a major outbreak. What most users don't realize is that for daily updates, they have to use another utility - 'Intelligent Updater' which has to be downloaded and installed manually. Thus, for most users, effectively the update window is 7 days.

Along with 'real time' updates, today there is a critical need for 'malicious code management' - especially for controlling outbreaks. To provide 'real time' updates and centralized malicious code management, a next generation technology is required. This is where Network Associates McAfee ASaP, based on patented Rumour Technology comes in. ASaP, provides continuous, online and real-time malicious code, and firewall/IDS protection. It also provides centralized enterprise-wide malicious code management. Subscribers receive continuous updates directly from AVERT Labs (world's foremost anti-virus Lab which discovered Code Red and Nimda), through SecureSynergy's NOC in Mumbai. The subscribers also receive comprehensive malicious-code management reports.

The ASaP model is particularly significant for mobile users. They receive continuous updates as soon as they connect to the Internet, wherever they are in the world.

 
 
Updated: 01 June 2004
 
 
SEND FEEDBACK ON THIS ARTICLE
 
 
 
 
 
 
 
Information Risk Management (IRM) Service for Industry
in partnership with SecureSynergy
IT SECURITY TRAINING
CII has designed courses for Board of Directors, CEOs, CFOs, CIOs and Management Decision Makers in areas affecting IT Security Governance and implementation of enterprise-wide security programs.
::. MUST  READ .::
Role of IT in Corp Governance
IT Security Governance
Information Security - A Business Enabler
IRM - A BPO Imperative

Say yes to
S T A N D A R D S  &  R E G U L A T O R Y
C O M P L I A N C E

Regulation establishes security duties and standards to foster better governance...
 
 
 
 
 
 
All rights reserved :: Confederation of Indian Industry (CII) © Copyright 2004-2008
Copyright  ::  Disclaimer  ::  Privacy