Related Links

Related Stories

  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace
  • What’s in store for 2010?
    The Noughties are behind us now, but memories of a decade of data breaches will continue to haunt the infosec professional. If only there was a way of knowing what the threat landscape would look like in the months to come. Well you’re in luck as Davey Winder has dusted off the crystal ball and spoken to a broad church of infosec professionals to get some informed predictions for 2010
  • Spamming the socially active - spam diversifies to Twitter, IM, SMS, etc
    Once poison found only in email accounts, spam is now polluting every form of electronic communication from IM to SMS and from blogs to tweets. But how well is it doing outside its natural domain? William Knight takes a look at non-email spam
  • Can the IT department survive Web 2.0?
    Risk-averse IT departments that are too cautious in their approach to Web 2.0 technologies such as social networking, online applications and cloud computing could be signing their own death warrants.
  • Educating children on data protection
    The use of biometrics and CCTV in school classrooms - installed to protect pupils - may just as easily put them at risk of other dangers. What, then, can be done to prepare our children for the big wide world of data protection? Rob Stringer reports…

Feature

Comment: Securing web 2.0 in the workplace

18 January 2010
Simon Morris, Pentura

Simon Morris, research and development director at Pentura looks at how the adoption of web 2.0 makes the job of keeping email and the web free from attacks, malware and spam even more difficult. Yet, simply closing access to unapproved tools can be short sighted as unhappy employees drift to rival businesses with more enlightened policies

Web 2.0 is growing with increasing momentum and businesses seem to be harnessing some of its benefits to bring them closer to their customers and improve overall brand experience. However web 2.0 as a concept is quite vague and is becoming all encompassing.

Firstly it is important for businesses to distinguish between web 2.0 social networks and web 2.0 functionality in the workplace; social media is very similar to web 2.0 the main difference is that social media focuses on people and web 2.0 focuses on content.

Social networks are heavily focused at keeping in touch with friends and sharing photos, video and chatting in real time. Using social networks such as Myspace, Twitter and Facebook in the workplace is arguably questionable in terms of how it benefits the business. Evidently organisations need to keep staff happy and not enforce draconian rules upon them; however providing such a distracting media in the workplace and encouraging its use can’t be beneficial.

Web 2.0 functionality however can be very beneficial. Using a combination of different mediums (web, audio, and video) to convey a message to new and existing clients can be used to great effect. A number of Pentura’s clients have started to use such techniques drawing on the principles of the social networking environments to provide a new canvas for marketing.

An example of this was a company that produces cosmetics, which used web 2.0 functionality to provide a feature rich website for customers to become members of if they were interested in the brand in question. Additionally members could liaise with each other via chat but also enter online competitions and win prizes.

The security question

The original question of security is significant in both instances as both use diverse integrated functionality to convey information. Social networking sites’ very essence is defined by feature rich functionality and this encompasses web, chat, audio, video, pictures and integrated applications. There are issues of personal data to consider with profile information but the most significant risks exist with the integrated applications as these can be hosted third party and not subject to any security or information assurance controls.

In the last 18 months it has been demonstrated that these applications can have malware or functionality issues, which have serious security implications.

Business are becoming more aware of the security risks associated with using web 2.0 however, existing security architectures have a limited ability to manage them effectively. Most block at a higher level, which inhibits useful functionality or just block the URL outright. Firewall technology mostly enforces policy at network layer with a degree of layer application functionality but again with limited effect.

Technologies are now starting to emerge, which offer granular control of web 2.0 functionality. Palo Alto Networks offer one such technology, which is currently unique in the firewall marketplace. It allows businesses to gain user application usage visibility and affect a policy to control web 2.0 applications from almost any aspect such as chat, email, apps and file transfer.

Companies that harness web 2.0 technology for their own use should make sure their application and website code is fully checked and written in a secure manner as experience shows the use of third party libraries can diminish a business’s security baseline and should be used prudently. Businesses need to understand the security issues of both web 2.0 and social networking as their use in the workplace seems to be here to stay.


Pentura Ltd, a UK risk management service provider, is exhibiting at Infosecurity Europe 2010, on 27- 29 April in its new venue Earl’s Court, London. The event provides a free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

 

This article is featured in:
Application Security Compliance and Policy

 

Comment on this article

You must be registered and logged in to leave a comment about this article.