About

This page contains a single entry from the blog posted on October 17, 2006 9:27 AM.

The previous post in this blog was Another reason to have a layered enterprise security strategy.

The next post in this blog is What is the right password strategy?.

Many more can be found on the main index page or by looking through the archives.

« Another reason to have a layered enterprise security strategy | Main | What is the right password strategy? »

Are five anti-virus softwares enough for an enterprise?

On October 5, 2006 a company in the UK, GFI, issued a press release titled "GFI warns one anti-virus engine is not enough to protect your business". They have recently published a report saying that one antivurs software is no longer sufficent for an enterprise. The report quotes "According to the 2006 FBI Crime and Security Survey, 97% of organizations have anti-virus software installed, yet 65% have been affected by a virus attack at least once during the previous 12 months. Network World cited studies that placed the cost of fighting Blaster, SoBig.F, Sober and other email viruses at $3.5 billion for US companies alone. Similarly a 2006 study by the British government found that 43% of companies in the United Kingdom were infected by viruses during 2005."

Their solution is of course their own product which can manage several different anti-virus vendors. Their thinking is that more is better.

While there may be some merit to this idea that the anti-virus software from one vendor might not catch all malware, there is no way that even with the best, most up to date, antivrius system in the world, that this will be enough.

A janitor who installs a hardware keyboard logger on your key users' computers at night, completely files underneath all the enterprise radar. A criminal with a sound dish can now record your office keystrokes and quickly depcipher your id and password.

The answer is to have a layered identity defence. "Battling Botnets and Rootkits - A Layered Identity Defense" describes the overall architecture required.

Beware vendors who claim their one product will solve the problem. It is likely to be breached.

Guy
www.authenticationworld.com
guy.huntington@authenticationworld.com

TrackBack

TrackBack URL for this entry:
http://www.authenticationworld.com/cgi-bin/blog/mt-tb.cgi/7

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)