Toolbox
Data Center Security Tools to Not Overlook
Endpoint technologies and virtualization software get a lot of ink these days, but here's a quick look at five other key security areas addressed by data-center tools
By Rick Cook
County Bank, a 40-branch bank based in Merced, Calif., runs an AS/400 and about 40 PC servers and uses Qualys to conduct regular scans on the servers.
"Having a tool like this is extremely important," says Charlie McClain, information security officer at County Bank. "The vulnerability picture in the Windows environment changes on a daily basis." He likes Qualys because it keeps up with those vulnerabilities, meaning he does not have to.
In addition to scanning the Windows servers daily, County Bank scans its AS/400 once a month.
Also on the market is Nessus, the open-source vulnerability scanner that is no longer included in the BackTrack CD because of kernel compatibility issues.
It's important to scan frequently. "Scan every 24 hours, looking for the silly human mistakes people make," says Ken van Wyk, founder and principal consultant at KRvW Associates, an Alexandria, Va.-based security consultancy. He says that changes in applications, configurations, servers or the network can accidentally open vulnerabilities as a side effect and need to be spotted early.
CSI Data Center
Vulnerability scanners are perhaps the best-known computer-forensics tools. Forensics tools range from basic log scanners to very elaborate programs that can examine the guts of your system at a deep level. The skill and technical knowledge needed to run these tools varies greatly. Serious forensics analysis is a job for experts, but just about anybody can use other simpler analysis tools, although interpretation may require special knowledge. Every CSO should have at least some basic forensics tools to use in the data center.
Perhaps the best example is the BackTrack 3 CD. The BackTrack 3 CD (www.remote-exploit.org/backtrack.html), a live CD containing a collection of open-source forensics tools. "One thing someone [who is handling data center security] should do is download BackTrack 3 CD, learn how to use it and learn how to create visibility into their network environment," says John Kindervag, a senior analyst at Forrester Research.
Plug the Leaks
Software that monitors the data that leaves the data center and attempts to prevent the inappropriate export of sensitive data is called data-leakage-protection software. Other names for this fairly new area are data loss prevention (DLP), information leak detection and prevention (ILDP), information leak prevention (ILP), content monitoring and filtering (CMF) or extrusion prevention system.
Data-leakage protection uses software that monitors what goes out of the data center and attempts to prevent the inappropriate export of sensitive data. It is attracting a lot of attention as companies shift focus from strict concentration on threats coming in, to what's going out of their organizations. "Protecting data by making sure it doesn't exit the company inappropriately is the key," says Quin, adding that data leakage protection is "outside the norm as it stands now but certainly something that has a great relevance to every organization."
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



