The Challange - Security Vs. Mobility

The overwhelming increase in the mobility of theThe first line of defense provides the following
corporate workforce and the availability of wirelessadvantages:
internet connections in airports, hotels, and coffee- Mobile code is not run - content arriving from the
houses, creates an unbearable challenge to ITinternet is not executed on these appliances it just
managers. Whenever employees, travelling with theirgoes or does not go through into the network. It
laptops, connect to a hotel hotspot, they are in factmakes it more difficult to attack as the mobile code
connecting their corporate computers to an unsecureddelivered by the hackers does not run on the
network, shared by hundreds of guests. This innocentappliances.
connection jeopardizes sensitive data and can bringCannot be uninstalled - Security attacks often start by
back security threats into the corporate network whentargeting the security software, while trying to uninstall
returned to the office. For this reason, IT managersit or stop its activity.
have adopted rigid security policies, creating a conflictSoftware-based security solutions, as any software
between the need for security and the productivity ofprogram includes an uninstall option that can be
the mobile workforce. For example, sometargeted. In contrast, the hardware-based security
organizations consider the returning laptops asappliances cannot be uninstalled as they are hard
"infected". The infected laptops are completelycoded into the hardware.
formatted and cleaned. Some allow dial-up- Non-writable Memory - Hardware-based solutions
connections-only (no Wi-Fi), while others go further tomanage the memory in a restricted and controlled
completely prohibit the connection of laptops to themanner. The security appliances can prohibit access to
Internet outside the corporate network.its memory, providing greater protection against
This unbearable conflict between security and mobilityattacks on the security mechanism.
can only be solved if the mobile force is equipped with- Controlled by IT personnel - The security appliances
the same level of security as they have inside theare controlled by IT, who constantly maintains the
corporate network. To understand what this means,highest security policies and updates.
we should examine the level of security that is- Performance - The security appliances are optimized
maintained inside the corporate networks.for maximum security and operate independently from
Corporate Network - Two Lines of Defensecomputers in the network, not degrading the
Corporate users enjoy higher security levels inside theperformance of the desktops or consuming their
corporate network because they operate behind tworesources.
lines of defense. The first line of defense, is a set ofConsequently, the corporate PCs reside in a secured
robust security appliances, installed at the IT center andenvironment. If the security is breached, at least the
exclusively controlled by the IT department. It is largelydamage stops at the gateway. The first line of
based on a comprehensive set of IT securitydefense prevents threats from entering the corporate
appliances running secured and hardened OS, withnetwork. While the second line serves as a precaution
Firewall, IDS, IPS, Anti Virus, Anti Spyware,and help defend against threats that may have
Anti Spam and Content filtering. The second line isalready entered the network (e.g. emails). But the real
based on the Personal FW and Anti Virus softwareproblem starts when the corporate PCs go in and out
installed on end-user's computers.of this secured environment. Outside the corporate
The first line of defense completely isolates the usernetwork they are at the frontline with no first line of
at the physical and logical layers.defense. The problem intensifies as they return,
Unlike PCs, these appliances are equipped with abypassing the first line of defense as they enter the
Hardened operating systems that do not have securitynetwork. These laptops can be considered as the
holes, "back-doors", or unsecured layers. They aregreatest threat because they unknowingly infiltrate
designed for a single purpose, to provide security.security threatsinto the supposedly safe network.