<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Taking the Complexity out of IT Security</title><link>http://blogs.technet.com/cdnitmanagers/archive/2008/01/29/taking-the-complexity-out-of-it-security.aspx</link><description>Once upon a time, securing your IT environment meant sticking a firewall between your network and the Internet. These days there's a lot more to it. IT security needs to be implemented on multiple levels and actively managed which makes things a tad more</description><dc:language>en-CA</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Taking the Complexity out of IT Security</title><link>http://blogs.technet.com/cdnitmanagers/archive/2008/01/29/taking-the-complexity-out-of-it-security.aspx#2810286</link><pubDate>Fri, 01 Feb 2008 22:03:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2810286</guid><dc:creator>George Bailey</dc:creator><description>&lt;P&gt;IT Security is essentially Information Security (everything else - physical security, network security, etc. are supportive of the overarching objective i.e. protection of the information) - and the very nature of information makes IT security inherently complex.&lt;/P&gt;
&lt;P&gt;The history of cryptography (one of the oldest information protection methods) is quite instructive. &amp;nbsp;The speed with which the complexity of an already complicated task increased as technology availability, transaction frequency and user numbers increased. Simon Singh's "The Code Book" (ISBN-13: 978-1857028898) is a good non-geek source.&lt;/P&gt;
&lt;P&gt;The main reason why the complexity of IT Security will only increase is that we did not cater for the amazing rapidity with which modern IT has developed and been adopted, which has led to (you guessed it) "technology availability, transaction frequency and increase of user numbers" and the inescapable complexity of IT security.&lt;/P&gt;</description></item><item><title>re: Taking the Complexity out of IT Security</title><link>http://blogs.technet.com/cdnitmanagers/archive/2008/01/29/taking-the-complexity-out-of-it-security.aspx#2828937</link><pubDate>Tue, 05 Feb 2008 07:21:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2828937</guid><dc:creator>Rick Omar Kazi</dc:creator><description>&lt;p&gt;George,&lt;/p&gt;
&lt;p&gt;The last line in your comment hit the nail on the head.&lt;/p&gt;
&lt;p&gt;IT Security can be made less complex if we combine people (awareness), products (secure OS) and processes. &lt;/p&gt;
&lt;p&gt;Security is best deployed in 4 easy layers : Network, Endpoint, Server and Application.&lt;/p&gt;
&lt;p&gt;Windows 2008 actually provides enhancements that are built into the core product, so extra products are not needed, simplifying IT managers lives quite alot.&lt;/p&gt;</description></item></channel></rss>