Thursday, September 17, 2015

Why startup leaders need to set the tone for security
Amid new calls from federal authorities for prioritizing security in tech startups, industry experts stress the importance of having firm leaders set a cultural tone.

CIO | Sep 16, 2015 6:34 AM PT
·         Security
Federal consumer-protection authorities have called on the entrepreneurs building tech startups to prioritize cybersecurity from the earliest stages of the development process.
But a variety of factors -- cost, lack of technical expertise, rush to market, etc. -- can make security seem like more of a burden or an impediment to the startup's growth than anything else.
At a recent event convened by the Federal Trade Commission, industry insiders emphasized the importance of incorporating security as an integral part of any company's operations, not just the services or applications that it produces.
At startups in particular, which are often led by a founder/CEO whose personality can to a great degree define the culture of the organization, it is crucial that the firm's leaders establish the expectation that security is a company-wide priority.
"I think company founders, management are really critical to developing a culture," says Devdatta Akhawe, a security engineer at Dropbox. "In my experience, the companies that have responded well and responded seriously to security issues are often the ones where the founders are driving this sort of culture and these sort of values."
It's worth noting that the idea that the founders should set the tone from the top on security is hardly confined to startups. Frank Kim, chief information security office at the SANS Institute, recalls the predicament of Microsoft in the late 1990s and the early part of last decade. In 2002, when then-CEO Bill Gates issued an all-hands warning about the need to prioritize security in the company's ubiquitous software, Microsoft was viewed as a "laughing stock of the security industry," Kim says. The result of Gates' warning was Microsoft's Trustworthy Computing initiative, a concerted effort that considerably improved the company's security posture.
In part, security became a priority at Microsoft because the company's customers demanded it. And fledgling startups trying to carve out a slice of market share can ill afford a data breach or the reputational hit that comes from the perception that its applications aren't secure -- customers are likely to vote with their feet.
Making security in a startup a high-level goal
It seems easy enough to designate security a high-level goal within a startup, but how should that work in a practical sense?
Window Snyder, CSO at Fastly and an experienced hand at security who has done stints at Apple and Mozilla, emphasizes the importance of starting from the earliest stages of the development process and training the engineering team on some basic tenets of secure programming.
Then, she suggests that companies implement a peer review process whereby the security experts and others get a chance to kick the tires on a particular feature before it is released to the public, noting the benefits that can emerge from bringing disparate teams together to focus on security.
Bottom of Form
"That creates a sense that it's everyone's job," Snyder says.
The argument for more clearly defined security roles
That maxim that everyone is responsible for promoting security on its face sounds simple enough, but not everyone is on board. Count among the dissenters Jonathan Carter, a veteran security professional and software engineer who argues for more clearly delineated roles within the development team.
"I take a slightly more controversial approach," Carter says. "Whenever I see something like 'security is everyone's responsibility,' that makes me cringe inside because, really, that means security is no one's responsibility. It's the diffusion of responsibility psychological principle, where suddenly it's on no one's radar and it's just this amorphous concept. So as a software engineer, I would say your responsibility is to identify issues and confer with your local security champion within your immediate team."
There was scant disagreement, however, on the broader point that startups and mature companies alike would do well to elevate security as an organizational priority.
And to the concern that a more security-intensive development process would carry more cost than a cash-strapped startup could afford -- to say nothing of the delay in time to market -- Akhawe urges firms to consider the alternative, the disastrous effects of a breach or the release of a product with glaring vulnerabilities.
"Security's much, much, much cheaper the earlier you do it," he says.
This story, "Why startup leaders need to set the tone for security" was originally published by CIO.

Thursday, September 3, 2015

New Networking Trends

In the not-too-distant past, the networking industry focused a lot on hardware speeds and feeds. Networking gear was judged on how many packets it could process per second and how many ports per device. Today, the industry's focus is shifting to software, code, and open systems.
Software-defined networking, while still far from mainstream, is slowly making inroads into the enterprise. A survey of 153 midsize and large North American enterprises by Infonetics Research, now part of IHS Inc., found that 79% plan to have SDN in live production in their data centers by 2017. Garter predicts that by the end of next year, more than 10,000 enterprises will have deployed SDN in their networks.
Along with SDN, there's a lot of talk about open standards, open protocols and open systems. One aspect of the open networking movement continues to gain momentum as the number of alternatives to proprietary switches with tightly integrated software and hardware grow.
The Facebook-led Open Compute Project has helped lead the charge towards disaggregating the network. The social media giant recently proposed a specification for its open Wedge top-of-rack switch to OCP, and Accton Technology's Edge-Core subsidiary is offering a TOR switch based on the Wedge design. Meanwhile, HP is partnering with Accton and Cumulus Networks on its new line of open network switches, which HP says gives customers a choice of hardware and software on branded switches with HP support.
Infonetics expects the white-box switch trend to make big strides over the next few years as more companies seek the agility and flexibility demonstrated by Internet giants like Facebook and Google. The firm forecasts that bare-metal switches will make up nearly a quarter of all data center ports shipped worldwide in 2019, up from 11% last year.
While a lot of conversations in networking revolve around open networking, SDN and network automation, networking professionals are delving into many other areas. Enterprises are migrating to the 802.11ac WiFi standard and the transition to IPv6 continues to loom.
All these networking trends will be featured at Interop Las Vegas April 27 to May 1. Continue on to find out what you can expect to learn at Interop and what networking luminaries will share their views on the technologies poised to radically change the networking landscape.

Article by: Marcia Savage is the managing editor for Network Computing, and has been covering technology for 15 years. She has written and edited for CRN and spent several years covering information security for SC Magazine and TechTarget.