Welcome!

Industrial IoT Authors: Pat Romanski, Elizabeth White, Liz McMillan, Ed Featherston, William Schmarzo

Related Topics: Cloud Security, Java IoT, Industrial IoT, Microservices Expo, Microsoft Cloud, Containers Expo Blog, @CloudExpo

Cloud Security: Article

Network Security Operations in an Increasingly Application-Centric World

It’s Bridge-Building Time

Using technology to break down corporate silos within IT is not a new concept, but seeing it in action is a testament to the power technology has to transform business. One area of IT that is currently undergoing such a transformation is network security operations. Over the past few years, complexity has been the catalyst for automating critical facets of network security operations. Having reaped the benefits that come with automating outdated manual processes, administrators have found that a deeper challenge exists: network security operations as whole must evolve in order to account for an increasingly application -centric enterprise.

Business-critical applications such as CRM, ERP, Payroll and HR systems - not to mention sophisticated e-commerce and back-end transaction processing systems - have become the lifeblood of the modern enterprise. These applications need to be up and running 24/7. Now that a much-needed wave of automation has given network security operations teams more breathing room, they have found that one of the most important things the business wants from them is to ensure the connectivity requirements of these business-critical applications are being met. Commissioning applications, de-commissioning applications, managing a major upgrade or bug fix, or rolling out a new enterprise application are all items that can impact application availability. Additionally, mergers, acquisitions, data center consolidations and other and technology transitions require IT departments to translate application connectivity requirements into firewalls policies that are secure and if applicable, align with any internal or regulatory mandates.

While these tasks are mainly the charter of applications teams, network security teams have become increasingly involved in managing these aspects of application connectivity. In fact, managing application connectivity requirements has become the main reason rule (a.k.a policy) changes are made to network devices such as firewalls, switches, routers, web proxies and load balancers. However, these devices were not necessarily designed to manage application connectivity as a specific business requirement, so extracting the necessary information needed to manage application connectivity is extremely difficult. Application-connectivity related data is parsed across numerous network devices and rules within those devices. It is also constantly changing.

Furthermore, it is not something that operations teams can create from scratch or in a vacuum. They need to communicate with application owners in order to get information such as server IP addresses, port numbers, database, LDAP, authentication and other servers needed to ensure the application runs smoothly, and they need to make sure that application owners are aware of and account for relevant changes that impact other aspects of application management.

However, network security teams and application teams have not had much interaction. While these two groups now share a common need to access and manage application connectivity-related data, there is little, if any, common ground between them. They have different agendas, use different lingo, and are measured on different criteria. Network Security teams care about network security, regulation compliance and risks. Applications teams care about service delivery, application up-time and business continuity.

This has presented a new set of challenges - business process and communication issues that require attention. It's no secret that these two teams must find a way to work in harmony to implement increasingly complex security requirements without compromising the organization's business objectives. This is where technology can be used to quite literally to bridge the existing gaps that exist between these two groups. It is a people, as opposed to a device-oriented approach to managing IT. And it is in this capacity - the use of technology to break down existing silos within IT - where technology can be truly transformative, in the very best sense of the word.

While Next Generation firewalls have introduced the concept of application-awareness to network security, both network security operations teams and application teams require application connectivity-awareness. In order to achieve it they need to change their whole approach to their jobs, and start collaborating with each other. But until these two silos are aligned with a single set of objectives, they are sure to continue along parallel lines. The good news is that this problem has now reached critical mass, and the market is responding. Good automation usually accomplishes two things - it either simplifies complexity or simplifies processes. While both are equally important, there is something to be said for using technology to bring people together. It's good to see process automation happening in the network security operations world. It's time to knock down the walls that prevent network and application administrators from communicating the way the need to in an application-centric world.

"Something there is that doesn't love a wall, That wants it down..."

--Robert Frost, Mending Wall

More Stories By Shaul Efraim

Shaul Efraim is Vice President of Marketing and Business Development at Tufin Technologies. He brings more than 18 years of results-oriented industry experience in key sales and marketing management roles. He has driven Tufin’s message through the creation of powerful channel, customer relations and marketing programs, highlighting the company’s unmatched expertise in firewall change management solutions and dedication to technical excellence.

Previously, Shaul held positions as various product management and technical marketing roles at Check Point Software, as well as PortAuthority Technologies and Eastronics Company. With a rich technical and marketing background, he holds a degree in Industrial Engineering from Tel Aviv University.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
In addition to all the benefits, IoT is also bringing new kind of customer experience challenges - cars that unlock themselves, thermostats turning houses into saunas and baby video monitors broadcasting over the internet. This list can only increase because while IoT services should be intuitive and simple to use, the delivery ecosystem is a myriad of potential problems as IoT explodes complexity. So finding a performance issue is like finding the proverbial needle in the haystack.
The 19th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Digital Transformation, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportuni...
Large scale deployments present unique planning challenges, system commissioning hurdles between IT and OT and demand careful system hand-off orchestration. In his session at @ThingsExpo, Jeff Smith, Senior Director and a founding member of Incenergy, will discuss some of the key tactics to ensure delivery success based on his experience of the last two years deploying Industrial IoT systems across four continents.
The Internet of Things will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, demonstrated how to move beyond today's coding paradigm and shared the must-have mindsets for removing complexity from the develo...
SYS-CON Events announced today that MangoApps will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. MangoApps provides modern company intranets and team collaboration software, allowing workers to stay connected and productive from anywhere in the world and from any device.
IoT is rapidly changing the way enterprises are using data to improve business decision-making. In order to derive business value, organizations must unlock insights from the data gathered and then act on these. In their session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, and Peter Shashkin, Head of Development Department at EastBanc Technologies, discussed how one organization leveraged IoT, cloud technology and data analysis to improve customer experiences and effi...
The IETF draft standard for M2M certificates is a security solution specifically designed for the demanding needs of IoT/M2M applications. In his session at @ThingsExpo, Brian Romansky, VP of Strategic Technology at TrustPoint Innovation, explained how M2M certificates can efficiently enable confidentiality, integrity, and authenticity on highly constrained devices.
In today's uber-connected, consumer-centric, cloud-enabled, insights-driven, multi-device, global world, the focus of solutions has shifted from the product that is sold to the person who is buying the product or service. Enterprises have rebranded their business around the consumers of their products. The buyer is the person and the focus is not on the offering. The person is connected through multiple devices, wearables, at home, on the road, and in multiple locations, sometimes simultaneously...
“delaPlex Software provides software outsourcing services. We have a hybrid model where we have onshore developers and project managers that we can place anywhere in the U.S. or in Europe,” explained Manish Sachdeva, CEO at delaPlex Software, in this SYS-CON.tv interview at @ThingsExpo, held June 7-9, 2016, at the Javits Center in New York City, NY.
"We've discovered that after shows 80% if leads that people get, 80% of the conversations end up on the show floor, meaning people forget about it, people forget who they talk to, people forget that there are actual business opportunities to be had here so we try to help out and keep the conversations going," explained Jeff Mesnik, Founder and President of ContentMX, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
Internet of @ThingsExpo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 19th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world and ThingsExpo Silicon Valley Call for Papers is now open.
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discussed how businesses can gain an edge over competitors by empowering consumers to take control through IoT. He cited examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He also highlighted how IoT can revitalize and restore outdated business models, making them profitable ...
"delaPlex is a software development company. We do team-based outsourcing development," explained Mark Rivers, COO and Co-founder of delaPlex Software, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
We all know the latest numbers: Gartner, Inc. forecasts that 6.4 billion connected things will be in use worldwide in 2016, up 30 percent from last year, and will reach 20.8 billion by 2020. We're rapidly approaching a data production of 40 zettabytes a day – more than we can every physically store, and exabytes and yottabytes are just around the corner. For many that’s a good sign, as data has been proven to equal money – IF it’s ingested, integrated, and analyzed fast enough. Without real-ti...
I wanted to gather all of my Internet of Things (IOT) blogs into a single blog (that I could later use with my University of San Francisco (USF) Big Data “MBA” course). However as I started to pull these blogs together, I realized that my IOT discussion lacked a vision; it lacked an end point towards which an organization could drive their IOT envisioning, proof of value, app dev, data engineering and data science efforts. And I think that the IOT end point is really quite simple…
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
Big Data, cloud, analytics, contextual information, wearable tech, sensors, mobility, and WebRTC: together, these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at @ThingsExpo, Erik Perotti, Senior Manager of New Ventures on Plantronics’ Innovation team, provided an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it ...
A critical component of any IoT project is what to do with all the data being generated. This data needs to be captured, processed, structured, and stored in a way to facilitate different kinds of queries. Traditional data warehouse and analytical systems are mature technologies that can be used to handle certain kinds of queries, but they are not always well suited to many problems, particularly when there is a need for real-time insights.
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
Is your aging software platform suffering from technical debt while the market changes and demands new solutions at a faster clip? It’s a bold move, but you might consider walking away from your core platform and starting fresh. ReadyTalk did exactly that. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, will discuss why and how ReadyTalk diverted from healthy revenue and over a decade of audio conferencing product development to start an innovati...