Security outsourcing or secure outsourcing?

Click here to load reader

Embed Size (px)

Transcript of Security outsourcing or secure outsourcing?

  • 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing 1/50

    -

  • 3/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 4/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 5/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    4

    18

    20

    21

    27

    28

    34

    34

    0 5 10 15 20 25 30 35 40

    247

    ?

    : Forrester Research

  • 6/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    15-20%

    10-15% ,

    5-10%

    15-20% Threat Intelligence

    10-15%

    5-10%

    0-5%

    25-30%

    15-20% / compliance

    10-15%

    5-10% IAM : Forrester Research

  • 7/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 8/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ,

    , ,

    ( ) () ()

    , 2-

    , ,

  • 9/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    Threat Intelligence

    Cisco Intellishield Alert, Cisco SIO, SecurityLab Alerts

    Cisco ScanSafe, WebSense, Google

    compliance

    Positive Technologies (PCI DSS, )

    Positive Technologies (, Web)

    Cisco, Orange,

  • 10/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 11/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    /

    BYOPC

  • 12/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    5

    ,

    DRM

    DLP

  • 13/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    MS Terminal Services, Citrix XenApp/XenDesktop, VNC

  • 14/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    (- ) ( e-mail)

    BlackBerry, Motorola Good Windows Mobile Symbian

  • 15/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ,

    VMware ACE, Cisco Secure Desktop, Microsoft App-V

    , Windows

  • 16/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ,

    Adobe LiveCycle Rights Management ES2, Oracle Information Rights Management, EMC Documentum Information Rights Management

    ,

  • 17/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ,

    Cisco E-mail Security Appliance, Infowatch Traffic Monitor, RSA DLP

  • 18/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 19/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    SaaS, PaaS, IaaS XaaS

    Software-as-a-

    Service

    Google Apps, Salesforce.com

    Platform-as-a-

    Service

    MS Azure, Google App

    Engine

    Infrastruc-ture-as-

    a-Service

    Amazon EC2, co-location

  • 20/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    33

    33

    31

    29

    33

    28

    42

    41

    39

    39

    35

    32

    23

    19

    24

    25

    25

    36

    0% 20% 40% 60% 80%100%

    ,

    , ,

    ,

    ,

    : Forrester Research

  • 21/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    ERP

    Service Desk

    HRM

    (ORM)

    (SRM)

    (SCM)

    Web 2.0

  • 22/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    36

    30

    23

    23

    20

    19

    18

    18

    16

    19

    0 5 10 15 20 25 30 35 40

    privacy

    ?

    : Forrester Research

  • 23/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    !

    -

    -

    IaaS PaaS SaaS

    VM VM VM VM VM

    -

    -

    -

  • 24/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    , ,

  • 25/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    SaaS, hosted service, MSS

    privacy

  • 26/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    identity

    Privacy

  • 27/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ()

    ompliance

  • 28/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    ?

    ?

    ?

    ?

    ?

    ?

  • 29/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ()

    ? ?

    ,

    ?

  • 30/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    ? ?

    ?

  • 31/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    identity

    ? ?

    ,

    ?

    ?

    SSO? ?

    ? ?

  • 32/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    247?

    ?

    ?

    ?

    ?

  • 33/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    SLA ( )

    ?

    DDoS

  • 34/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    OWASP

    ?

    Web Application Firewall

  • 35/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 36/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    Privacy

    ?

    ? ? ?

    ?

    , ..

    ?

  • 37/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    ?

    ?

  • 38/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    ? ?

    ? ?

  • 39/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    Compliance

    ? ?

    ?

    ?

    ISO 27001

    PCI DSS

  • 40/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    SLA?

  • 41/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    , ?

    ?

    ?

    ?

    , , ?

  • 42/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    ? ?

    ?

    ? ? ?

    ?

  • 43/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 44/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 45/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

  • 46/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ( XaaS)

    Platform

    as a Service

    Infrastructure

    as a Service X

    as a Service Software

    as a Service

  • 47/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    Platform

    as a Service

    Infrastructure

    as a Service X

    as a Service Software

    as a Service

  • 48/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    Bord

    erle

    ss

    Da

    ta C

    en

    ter

    3

    Bord

    erle

    ss

    Inte

    rnet

    2

    Bord

    erle

    ss

    En

    d Z

    on

    es

    1

    !

    (Access Control, Acceptable Use, Malware, Data Security) 4

    Platform

    as a Service

    Infrastructure

    as a Service X

    as a Service Software

    as a Service

  • 49/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing

    ?

    [email protected] : +7 495 961-1410

    http://lukatsky.blogspot.com/

  • 50/50 2008 Cisco Systems, Inc. All rights reserved. Security outsourcing