Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Enterprise Security Is A Matter Of Policy
Articles

Why Enterprise Security Is A Matter Of Policy

ISBuzz TeamBy ISBuzz TeamDecember 7, 2017Updated:December 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Browser security control
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security policies are as critical to safeguarding your networks as any new cybersecurity product.  Joanne Godfrey, director of communications for AlgoSec explains how policies can be better managed

Ever since the first firewalls were deployed on business networks in the early 1990s, enterprise security goals haven’t really changed:  keep the bad guys out, and ensure that only authorized users and software are allowed to communicate over approved network paths.  Sounds simple enough, right?  And in those early days, those goals were relatively easy to achieve.

Networks were smaller and less complex, with fewer devices, business applications and external connections.  So, the organization’s network security policies that governed how firewalls, proxy servers and other security devices work were simpler.  They needed only a relatively small set of rules to control what traffic should be blocked, what should be allowed, and where it’s allowed to go to enable security, ensure compliance and drive business productivity.

Fast forward 25 years, and networks have grown dramatically in size and complexity, with business applications being introduced and changed rapidly to support more users and new functionality.  Enterprise adoptions of virtualized and cloud infrastructures have introduced even more new network connectivity flows that need to be managed to keep applications secure.  And the threat landscape has changed almost beyond recognition, which means more security products are deployed to counter new threats.

Traffic control problems

As a result, the security policies that control network devices and traffic have grown massively.  They now typically comprise hundreds or even  thousands of firewall rules – making it increasingly challenging to maintain those policies, and balance the needs of the business with the need to keep it as secure as possible.  Just to keep up with business demands, network and security teams can find themselves managing hundreds of policy change requests a week.

With this growing volume and frequency of changes, continuing to rely on error-prone, manual processes to manage network security policy changes is too costly, time-consuming and inefficient.  What’s more, it dramatically increases the potential for misconfigurations and mistakes that lead to application outages, security holes and compliance violations.  In our 2016 State of Automation in Security” survey, 20% of organizations had experienced a security breach, 48% an application outage, and 42% a network outage as a result of a misconfiguration caused by a manual security-related process.

So it’s clear that organizations need to change the way that they manage their security policies, if they want to keep up with the speed of business – especially as more companies migrate applications to the cloud and adopt DevOps processes to help them develop and deploy new applications and functions faster. So how should they go about it?

 

Automation advantages

The key is to automate policy changes using a management solution.  An effective solution will provide holistic visibility across the enterprise network and the applications that run across it, enabling IT teams to see all the network and security devices, applications and their connectivity flows – whether on-premise or in private or public clouds – in a single pane of glass.

The solution will understand the rules and syntax used by the different network security devices – including traditional and next-gen firewalls and routers and cloud security controls – and manage them holistically from a single console, giving IT teams centralized control of all the ‘traffic lights’ on their networks, and enabling them to eliminate the time-consuming errors and problems that result from manual change processes.

 

It’s all about the applications

As the most common trigger for policy changes are changes to an application, it’s critical that teams understand exactly what devices and connectivity each application needs in order to function correctly and deliver its benefits, while remaining secure.  Therefore, the automation solution should be able to automatically discover and map the connectivity flows for all of the enterprise’s business applications, to show IT and security staff exactly how data flows across the network.  This application-centric approach helps teams to focus their efforts on what really matters to the business.

The automation solution should also enable IT teams to perform proactive risk analysis on planned application connectivity or security policy changes before they are made, to ensure that they don’t introduce security gaps or compliance violations.  Then, if no exceptions or issues are identified, the approved changes can be rolled out to the relevant security devices with zero touch – thereby saving significant time, effort, and most importantly helping to prevent misconfigurations which cause outages and security holes.  The solution should automatically document all these changes for audit purposes – and to help demonstrate compliance with the growing ‘alphabet soup’ of regulatory standards.

By taking an application-centric view of network security, the security policy management solution can also be used to accelerate incident response processes in the wake of cyberattacks or outages.  Linking the policy management solution to SIEM systems and vulnerability scanners adds vital context to information about incidents, enabling network and security teams’ actions to be prioritized according to the risk and impact on critical business applications.

In conclusion, automating security policy management delivers a stronger security posture across organizations, enables business continuity, accelerates digital transformation initiatives such as migrating applications to the cloud, and streamlines DevOps processes by supporting team collaboration.  Enterprise security truly is a matter of policy.

[su_box title=”About Joanne Godfrey” style=”noise” box_color=”#336588″][short_info id=’71131′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Cloud Security Controls Explained: A Definitive Guide

March 19, 20269 Mins Read

From VPS to Phishing: Darktrace Exposes SaaS Hijacks through Virtual Infrastructure Abuse

August 22, 20255 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}