tfh
Volume 19, Number 11 -- March 15, 2010

IBM Wins Kudos for Work in Security

Published: March 15, 2010

by Alex Woodie

IBM is doing its best to foster a new company saying: "Nobody gets fired for buying IBM security." After being named the best security company by a leading security magazine, Big Blue confirmed why it's among the leading security research, consulting, and product development organizations when it unveiled a slew of new SIEM and network security tools, completed another security-related acquisition, and announced the formation of the IBM Institute for Advanced Security. Not bad for a week's work.

The IT security-focused SC Magazine (www.scmagazine.com) named IBM the "best security company" of the year for 2010 two weeks ago at the RSA conference in San Francisco. Al Zollar, head of IBM's Tivoli division (and former general manager of the iSeries business), accepted the award on behalf of the company.

The magazine noted several reasons why IBM deserved the award. These included 50 years of work in the IT security business; its very secure databases, applications, operating systems, storage, and servers (including i/OS and z/OS servers, widely viewed as the most secure in the industry); and its "comprehensive" security solutions and services offerings, which run the gamut and include: compliance, identity and access management, networks, threat prevention, systems security, e-mail, encryption, virtualization, and cloud security.

To put it simply, IBM is a huge presence in the security business. Through its software and services, IBM managed more than 7 billion security events each day. Its X-Force branch employs more than 15,000 researchers, who probe IT systems for new security vulnerabilities, and keep the database of 48,000 known problems up-to-date. IBM currently holds more than 3,000 patents in the security business. More than 4,000 customers around the world outsource their security to IBM.

In other words, IBM does it all in security. "Through an end-to-end approach to security across people and identity, data, applications, infrastructure, compliance and the physical infrastructure, IBM's security capabilities are among the top in the industry," the magazine writes. "With multiple leadership awards in market presence and technology innovation, IBM is able to offer more than 120 security products and the experience of over 15,000 researchers, developers, and SMEs [small and medium-sized enterprises] focused on security initiatives."

With that said, IBM didn't take home any of the individual awards SC Magazine handed out for top products, including "best anti-malware solution" (won by McAfee), "best encryption solution" (won by PGP Corp., "best enterprise firewall" (won by Check Point Software Technologies), "best IPsec/SSL solution" (won by Barracuda Networks), "best SIM/SIEM solution" (won by ArcSight), or a dozen other categories.

But then IBM did something that reminded us why it's one of the safest bets in the security business: It went out and bought another security company that shows promise in its particular niche. In this case, it was National Interest Security Company (NISC), which IBM had announced its intention to acquire in January. The company, which is based in the Washington D.C. suburb of Fairfax, Virginia, does a lot of work providing security consulting services to the federal government, in addition to other branches of government and companies in the defense, healthcare, energy, logistics, and security industries. (That's right: NISC provides security for the security companies.) NISC had 1,000 employees, and will operate as a subsidiary of IBM's Global Business Services unit.

NISC was IBM's eighth security-related acquisition since the $1.3 billion acquisition in October 2006 of Internet Security Systems (ISS), the Georgia developer of network security tools that also netted IBM the ISS X-Force security research group. The list of buys (and planned buys) includes:

  • the February 2010 announcement of its intent to acquire Initiate Systems, an Illinois developer of master data management (MDM) software
  • the September 2009 acquisition of Guardium, a Massachusetts developer of database security tools
  • the July 2009 acquisition of Ounce Systems, a Massachusetts developer of security vulnerability detection tools
  • the March 2008 acquisition of Encentuate, a California developer of identity and access management software
  • the September 2007 acquisition of Princeton Softech, a New Jersey developer of security and management tools for databases
  • the July 2007 acquisition of Watchfire, a Massachusetts developer of security testing tools
  • and the January 2007 acquisition of Consul, a Dutch developer of audit and compliance tools

Many of these products have been integrated into the Tivoli division, the systems management and security software brand that itself is a former IBM acquisition.

IBM built on some of these acquisitions with a slew of new products announced at the RSA show. This includes a new Web application security service called Secure Web Gateway Service 2.0; a new service that allows IBM security to update CheckPoint firewall products; a new release of IBM's SIEM offering; a spam filter development tool called the Security Content Analysis SDK; a source code analysis tool for detecting security vulnerabilities, called AppScan Source Edition; a new client-agnostic e-mail encryption tool for Lotus Notes called Lotus Protector for Mail Encryption; a new security offering that looks for abuse of privileged user profiles, called Security Privileged Identity Management and Compliance Solution; and z/OS version 1.12, which IBM says offers more security capabilities.

IBM also announced the creation of its Institute for Advanced Security, a new group that will focus on bolstering cybersecurity around the world. The group has lofty goals, including getting organizations to build security into their applications from the beginning, instead of applying after-the-fact "bolt on" enhancements to close security gaps.

The group will "engage with government clients and other constituents to help them comprehensively understand how to develop and integrate effective security protections into the fabric of their critical systems and services," says Charles Palmer, the Institute for Advanced Security director, and also the chief technologist of cybersecurity and privacy for IBM Research.

With all the progress in IBM security offerings, one statement stands out. In an announcement, the company said: "Central to IBM's approach to addressing clients' security challenges is a shift in focus from securing assets to securing critical services."

This is a curious statement, as it generally goes against a growing consensus in the IT security business that organizations need to focus more on securing data, instead of concentrating efforts on network or infrastructure security. Security experts are even talking about a paradigm shift to protect the average organization's single most important asset--its data.

Perhaps IBM was hoping to put more emphasis on selling more security services? In any event, it will be interesting to see if the "best security" company in the world adopts the emerging consensus that more focus needs to be on securing the data itself, rather than the computers, applications, and networks in which it lives.


RELATED STORIES

Hackers Escalate Web Site Attacks, Despite Decline in Security Vulnerabilities

IBM Beefs Up Database Security with Guardium Buy

Web Site Vulnerabilities Continue Unabated, IBM X-Force Says

Decline In Vulnerabilities Belies Threat Increase, Microsoft Says in New Security Report

IBM Acquires Encentuate, Sets Up Security Software Lab

Surf's Up for Web-Based Organized Crime, IBM X-Force Says

IBM X-Force Says For-Profit Cyber Attacks to Increase in 2007



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
LOOKSOFTWARE

CONNECT AND GET CONNECTED!

Trevor Perry presents. . . Why Service-Enable?

Join Trevor Perry as he guides you through publishing and consuming web services with your existing applications. You will see live, practical examples and demonstrations of real customer experiences.

By viewing this webinar you will learn how to:

          · Identify and start your first web services project
          · Easily integrate with other applications & systems
          · Automate & streamline business processes
          · Quickly create components for SOA compliance

You will also learn how other IBM i customers have implemented service enablement.

View the on-demand webinar! - Get a Free White Paper

"looksoftware has allowed us to save hundreds of hours of development time and more importantly, thousands of dollars of expensive consulting effort to port existing, time-tested iSeries functionality over to the Microsoft Dynamics AX platform. With soarchitect, we can leave this already-working business logic intact on our System i and simply use web services to exchange data as needed with our new Dynamics AX system. . ."
George Hamin, Director of eBusiness & Information Systems, Subaru

Subaru service - enabled their i back-end to integrate with Microsoft's Dynamix and SharePoint.

www.looksoftware.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

PowerTech:  Strengthen your security. Get a FREE Compliance Assessment today!
New Generation Software:  NGS-IQ: Reporting & BI Software. Easy to Install. Easy to Use.
COMMON:  Join us at the annual 2010 conference, May 3 - 6, in Orlando, Florida

 

 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
Four Hundred Stuff
Genesta Offers Quick and Inexpensive Voice Enablement for i/OS Apps

Infor to Target BPCS Shops with 'Flex' Upgrade Program

Linoma Adds Tokenization to i/OS Encryption Tool

Vision Debuts PowerPack for POWER7 Migration

Quadrant Simplifies Workflows with IntelliChief 2.6.1

Four Hundred Guru
A Case for CASE

Job Descriptions: Underused and Underappreciated

Admin Alert: A Skeleton Checklist for Performing Power i Upgrades

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
March 6, 2010: Volume 12, Number 10

February 27, 2010: Volume 12, Number 09

February 20, 2010: Volume 12, Number 08

February 13, 2010: Volume 12, Number 07

February 6, 2010: Volume 12, Number 06

January 30, 2010: Volume 12, Number 05

TPM at The Register
Hedge fund suitor denies Novell asset sale rumors

Super Micro to launch AMD render cloud

CA eats Nimsoft cloud watcher

Swedes serve up flicks with KVM

Citrix tunes XenApp for Windows Server R2

Voltaire brings InfiniBand switch to the masses

Cisco 'forever changes internet' with... a router

Terracotta's Ehcache back-ends Hibernate

Tilera wins VC from Broadcom, Quanta, NTT

Yellow Dog Linux licks CUDA

iSuppli: Semi recovery a 'false spring'

BSkyB yanks more cash from HP's hide

THIS ISSUE SPONSORED BY:

Help/Systems
looksoftware
Vision Solutions
Linoma Software
VAULT400


Printer Friendly Version


TABLE OF CONTENTS
Old Code Meets New Ideas in Latest App Modernization Projects

IBM Cuts Prices for Upgrades to Power 595s

Power 750 Servers Running i Get SAP Benchmarks

Mad Dog 21/21: The Teahad Pilot, the Sycophant Senator, and IBM

Internal Disk Arrays Prop Up Storage Sales in Q4

But Wait, There's More:

Reader Feedback on IBM Starts Cutting U.S. Jobs Again . . . IBM Wins Kudos for Work in Security . . . Google Jumps Into Business Apps . . . IBM Debuts New Half Rack and BladeCenter E Chassis . . . The Top Brass at Big Blue Do Pretty Okay in 2009 . . .

The Four Hundred

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2010 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement