IDC’s Security Show Comes to Middle East
Thus far IDC’s fourth annual IT Security Road Show has received an excellent response with attendees in places like Bucharest and Zagreb calling it the “IT Event of the Year.” In February and March 2006, nearly 3,000 end users attended conferences in 12 cities.
To help drive the message home that many organizations are still under-equipped when it comes to IT security, the road show invited a number of high-profile experts and gurus to address classic and often overlooked security challenges as well as the risks imposed by new technologies. Headlining this year’s road show were two legends in IT security: Philip Zimmerman and Bruce Schneier. The inventor of one of the world’s leading and free e-mail encryption programs, Philip Zimmerman spoke about applying his more than two decades of experience to one of the most pressing issues of the day: How to ensure the security of VoIP. Schneier presented a method for rationally approaching IT security and addressing the tradeoffs involved in balancing security and convenience.
“One goal of our road show is to reveal that security is far more complex than most people realize,” said Tom Vavra, Research Director, IDC CEMA. “While a number of people come to the conferences looking for just firewall and antivirus applications, most quickly realize that these are components of a comprehensive set of solutions now required for adequately protecting business systems.”
IDC takes this message to the Middle East this month and next, stopping in Dubai on April 25, Kuwait City on May 2, Doha on May 9, Manama on May 15, Riyadh on May 21 and Amman on May 29.
“IT markets are developing rapidly in the Middle East and many businesses acquire complex IT systems all at once,” says Vinay Nair, Senior Analyst, IDC MEA. “This comes with a concomitant need for effective IT security. Unfortunately finding the right providers has also become difficult. Access to information isn’t all that helpful when there is too much of it, as there is on the Internet. Our events introduce users directly to those capable of helping secure their businesses.”
For more information about attending an IDC event contact Dana Dobrovodska at [email protected].
Identity Management Is a Big Concern
Sun Microsystems Middle East and Africa has identified identity management as one of the three most significant issues facing IT management in the GCC in 2006. At the recent Identity Management Summit in Dubai, Sun advocated a combination strategy of physical and logical identity management that would enable regional companies to protect access to their workplaces and IT infrastructures. The company has created a comprehensive identity management offering, which includes Java-based cards that can be used as national or company-specific identification as well as for payment and site entry, and a range of software that enables companies to integrate their IT security approach for centralized, cost-effective management.
Sun will be meeting with regional IT heads at security summits in Saudi Arabia and Qatar this week to highlight the need for a federated or uniform approach to both physical and IT security. The seminars will also include an overview from analyst group Forrester, which recently named Sun as “an identity management powerhouse,” citing the company’s Sun Java System Identity Manager software that offers businesses a “feature-rich solution” that also can be deployed quickly and cost-effectively. Reprints of the Q1 2006 Forrester Wave Vendor Summary are available on the Sun Microsystems Identity Management website at http://www.sun.com/identity/resourcecenter.
“Identity management, or the systems that give information and location only to the right people at the right time, is a critical consideration for banks, governments, airports, energy companies and other key vertical sectors in the Middle East,” said Jamie Bliss, Software Sales Manager, Sun Microsystems Middle East & North Africa. “As GCC governments consider creating national identity card schemes and businesses in the region stand to lose considerable amounts of money if information or assets fall into the wrong hands, an increasing number of regional organizations are making a centralized, self-service-enabled and affordable identity management solution a top priority in 2006.”
Universities Too Often Fail in Net Security
Trend Micro has launched an initiative to increase awareness on virus protection software in universities across the region. Speaking at the Women in IT conference organized by the Dubai Women’s College, Justin Doo, MD, Trend Micro Middle East and Africa, presented information on how viruses threaten university computing infrastructure, what students and staff need do to reduce this risk, and the benefits of having a more secure network.
Universities are particularly vulnerable as college computers often are more open to the public Internet than corporate systems and have high-speed connections to the web. Universities have also been the focus of other digital controversies.
“College campuses typically have thousands of computers and few staff dedicated to maintenance and security issues. Administrators say that makes it extremely difficult to monitor what’s happening on every single server and desktop connected to a university system,” explained Doo. “Academic institutions want to maintain the free exchange of ideas and information between faculty, students and researchers, both on campus and from university to university. At the same time you can’t just put a whole campus behind a firewall. That presents a challenge for keeping networks secure. The first priority toward maintaining the appropriate balance between security and freedom is to educate users on security risks.”
The current campaign is part of Trend Micro’s sustained commitment to help students develop the skills they need to participate effectively in a knowledge-based economy. Computer users at universities must understand that they are under attack from spyware, adware, hacker tools and other unsolicited applications that are often installed without the user’s permission or knowledge. Besides designating a senior administrator to oversee IT security, regional universities need to define, communicate, update and enforce university wide security policies. All network users must use antivirus software and security considerations should be included in every IT project.
“Universities also need to determine a proper strategy to apply software patches and security fixes in a timely, automated manner,” commented Doo. “Technology literacy is essential for innovation and economic growth. By creating awareness on online security challenges and the growing threat of spyware, we can help universities maintain their open environments so that students from the Middle East have the freedom to collaborate on research with universities in any other part of the world.”

