Published bimonthly, April 2004

 

Home    
Effectively Protecting the Network and Other Internal Resources


Enterprise security infrastructure is composed of the tools, technologies and tactics that are deployed to protect the network perimeter and internal resources. This includes a combination of effective technologies and best practices that include:

Firewalls, Intrusion Detection and Prevention
Advances in algorithms and network security processors have enabled the development of effective network security platforms that combine perimeter security solutions – such as firewalls, gateway antivirus tools, and network-based intrusion detection – into next-generation firewalls. Firewall technology is on the verge of its most significant change since the introduction of stateful packet inspection. This change will likely alter the vendor landscape and be driven by the emergence of deep packet inspection and other application capabilities.

Gartner recommends that midsize enterprises expend fewer resources on detecting intrusions and more resources on preventive measures to shield vulnerable systems and applications.

Mobile and Wireless Security
Mobile devices may be small, but their security issues are not. Mobile/wireless firewalls are incomplete products, crippled by the pressure to provide host and network intrusion prevention on devices that are constantly acquiring new vulnerabilities through changes in programming and poorly managed wired and wireless connections to external networks.

Additionally, antivirus products represent a mature, but incomplete market that suffers from a lack of integration with the functions performed by personal firewalls. And although encryption is essential, most enterprises focus too much on it as if it was a total solution. In the mobile/wireless world, encryption is a piece of access control and privacy that must be combined with strong, portable authentication. Also, because most mobile/wireless users are seeking a temporary connection, they do not need the strongest encryption algorithm.

IT Security Management
The charter of IT security management is to ensure the integrity of corporate networks, systems and data, and to demonstrate the due diligence that is required for audit and regulatory compliance. IT management must remediate external intrusions, fix lapses in administrative processes, and investigate unauthorized system access. Further, most enterprises are drowning in security data, yet desperate for information on which they can act.

IT security management technology provides automation that consolidates, aggregates and correlates security information from heterogeneous sources for real-time event management and historical analysis and reporting. Providers include large network and systems management vendors, broad-scope security software vendors, and a growing number of point solution vendors.

In today’s fast-changing environment, midsize enterprises must have a hardened interior and a layered approach to security, with an infrastructure that includes firewalls, intrusion detection and prevention, antivirus protection and content filtering, mobile and wireless security, encryption, and IT security management.

Speak with Gartner analysts about these key elements of security infrastructure face-to-face, and meet with some of the leading providers of security infrastructure products and services at Midsize Enterprise Summit. Click here to qualify to attend as our guest now.

Reference
Research Note
Client Issues for Security Infrastructure
Published: September 26, 2003
Authors: M. Nicolett, J. Girard, J. Pescatore, R. Stiennon, N. Schroder, A. Hallawell, Gartner, Inc.


..Subscribe
Continue to receive The Midmarket Report bimonthly --- register for your free subscription now! Click here.
..Q&A
Q: Is using two brands of antivirus software safer than using one?
A: Click here.

Complimentary Webcast
Branch Strategy – Making the Right Decisions
New requirements such as Check 21 are placing so many demands on Credit Unions that many are asking - Are my branches prepared for the future? Can I afford not to be? Join Stessa Cohen, Research Director, Gartner and Michael Stoeckert, CIO/CTO, EPL at this archived Webcast for an in-depth view of branch renewal, how Check 21 will affect the branch, and strategies to address the issues.

Peer Exchange Workshops
Want to discuss your top-of-mind IT management and technology concerns with nearly 500 of your peers from midsize businesses?


Midmarket Focus: Europe
Interview with Rob Brown....

Midmarket Perspective
Training Your Users on Spam Avoidance

Key Considerations When Evaluating Intrusion Prevention Products

 

Questions or comments? E-mail
midmarket@gartner.com


©2004 Gartner, Inc. and/or its affiliates. All rights reserved.
Reproduction of this publication in any form without prior written permission is forbidden. Gartner and Vision Events, a Gartner company, are registered trademarks of Gartner, Inc. or its affiliates. Other brands and trademarks are the property of their respective owners. All rights reserved.