SlideShare une entreprise Scribd logo
1  sur  2
06350<br />Worst Practices: Learning the Wrong Lessons from WikiLeaks<br />By Sean Gallagher<br />Sean Gallagher covers defense and public sector IT, as well as general IT, for C4ISR Journal, Internet Evolution, Ziff Davis, and NBC Digital Networks, and consults on web and social media. He is the author of The Packet Rat blog.<br />The dark cloud of the WikiLeaks debacle should have a bright silver lining. The exposure of classified Department of Defense and State Department data by WikiLeaks gives us a teachable moment on information security — not just for government agencies, but for any organization that stores, handles, and processes sensitive information.<br />The vast amount of classified data — over 75,000 Defense Department incident reports and more than 115,000 classified diplomatic cables — and the damage caused by their exposure reveals common flaws in how organizations typically handle sensitive information. But as with past data breaches, many organizations will learn the wrong lessons. And the actions they take as a result will make their organizations less productive and, perhaps, even less secure.<br />They’ll severely curtail information sharing within and between their organizations. They’ll put “additional safeguards” in place to prevent insiders from exposing sensitive data. They’ll do more briefcase checks, tighten password policies, and perform internal paper audits of policy compliance.<br />These knee-jerk responses to an event such as WikiLeaks aren’t best security practices in any sense of the word. Instead of simply putting more locks on more doors, organizations need to start with two things:<br />Find and fix the fundamental problems in how their workflow around sensitive data is regulated and monitored.<br />Find and fix the fundamental problems in how existing security policies are applied and enforced.<br />With the benefit of retrospect, we now have a foundation that can help prevent the next WikiLeaks-style breach.<br />Reduce network complexity to apply security policies consistently.<br />Many of the problems that made the WikiLeaks exploit possible were issues already being addressed by the DoD before the breach occurred. But because of the magnitude and heterogeneity of DoD’s networks, consistent implementation of security policies has proven difficult. Organizations can dramatically reduce security risks — even those posed by insider threats — by simplifying the physical complexity of their networks, and by reducing the number of supported configurations of systems they need to manage.<br />Use role-based access instead of clearance-level access and “communities of interest.”<br />The alleged WikiLeaks source reportedly was astonished by the “so broad and yet so rich” data set that was made available to him. He was an intelligence analyst with a unit in Iraq, yet much of the data he is alleged to have pinched — including State Department cables regarding diplomatic relationships with countries outside the region — were irrelevant to his role, despite his Top Secret/ SCI clearance. Even if some parts of the data he was working with were relevant to his role as an intelligence analyst in Iraq, there’s no conceivable reason that one analyst should have access to every document classified “Secret.” Likewise, there’s no reason for a business analyst to have access to customers’ credit card numbers when evaluating purchase patterns. In cases where there are legitimate needs for data across roles, organizations should put strict governance over auditing and continuous monitoring. Indeed, had the DoD compartmentalized information into VPNs (virtual private networks) within the secure network, the WikiLeaker’s alleged access could have been curtailed. Collaboration outside of specific geographic or operational areas of interest would not have been possible. By allowing collaboration with people actually working with data, and excluding them when their assigned tasks don’t include work with the data, the risk of a WikiLeaks-scale exposure is markedly diminished.<br />Continuously monitor information access.<br />Having an audit trail of who accesses what information when is not alone sufficient to prevent data breaches. It’s like an idiot light on a dashboard: It glows red after something happened. Organizations need to monitor what’s being done with data, and alert on behaviors that fall outside the norm. Data loss prevention (DLP) software can automate some of this monitoring. It can flag unusual volumes or types of data access by users, and prevent the transfer of metadata-tagged content from the network.<br />Control removable media.<br />DoD officials say the data exposed by WikiLeaks was downloaded to optical disks from a computer connected to the DoD’s Secret Internet Protocol Router Network (SIPRNet). In December, the DoD reinstated a ban against using removable media with classified systems, after dropping a ban that had been imposed after a 2008 malware attack on SIPRNet. Removable media can be locked down automatically through a number of security policy enforcement tools.<br />These steps only work if they’re consistently applied across the enterprise, constantly refined, and consistently automated. Even the most rigorous security practices and policies fail if they’re static.<br />As Sanjeev “Sonny” Bhagowalia, Deputy Associate Administrator of the General Services Administration’s Office of Citizen Services and Innovative Technologies, recently said, “Compliance is a beautiful place to hide, but it doesn’t mean you’re secure.”<br />The more automated the implementation and adjustment of security measures are to users, the more effective they’ll be in the long term. And the more transparent those changes are to use, the less that they’ll adversely impact the organization’s mission in the process.<br />For more information visit www.unisys.com ©2011 Unisys Corporation. All rights reserved. Specifications are subject to change without notice. Unisys and the Unisys logo are registered trademarks of Unisys Corporation. All other brands and products referenced herein are acknowledged to be trademarks or registered trademarks of their respective holders. Printed in United States of AmericaMarch 2011<br />
Worst Practices: Learning the Wrong Lessons from WikiLeaks

Contenu connexe

En vedette

Top 10 Mistakes in Behavior Change
Top 10 Mistakes in Behavior ChangeTop 10 Mistakes in Behavior Change
Top 10 Mistakes in Behavior ChangeMike Rother
 
Kata Creates Culture
Kata Creates CultureKata Creates Culture
Kata Creates CultureMike Rother
 
How to Deploy the Improvement Kata v7.0
How to Deploy the Improvement Kata v7.0How to Deploy the Improvement Kata v7.0
How to Deploy the Improvement Kata v7.0Mike Rother
 
Introduction to the Improvement Kata
Introduction to the Improvement KataIntroduction to the Improvement Kata
Introduction to the Improvement KataMike Rother
 
Two Mindset Obstacles to Effective Learning
Two Mindset Obstacles to Effective LearningTwo Mindset Obstacles to Effective Learning
Two Mindset Obstacles to Effective LearningMike Rother
 
Work Study: Method Study & Work Measurement
Work Study: Method Study & Work MeasurementWork Study: Method Study & Work Measurement
Work Study: Method Study & Work MeasurementHarinadh Karimikonda
 
Kata Slides & Graphics v4.1
Kata Slides & Graphics v4.1Kata Slides & Graphics v4.1
Kata Slides & Graphics v4.1Mike Rother
 
10 performance and scalability secrets of ASP.NET websites
10 performance and scalability secrets of ASP.NET websites10 performance and scalability secrets of ASP.NET websites
10 performance and scalability secrets of ASP.NET websitesoazabir
 
training & development ppt
training & development ppttraining & development ppt
training & development pptMonishaangel
 
Methods Of Training
Methods Of TrainingMethods Of Training
Methods Of Trainingjitu
 
Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)
Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)
Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)Jodie Harper
 

En vedette (16)

Top 10 Mistakes in Behavior Change
Top 10 Mistakes in Behavior ChangeTop 10 Mistakes in Behavior Change
Top 10 Mistakes in Behavior Change
 
Kata Creates Culture
Kata Creates CultureKata Creates Culture
Kata Creates Culture
 
How to Deploy the Improvement Kata v7.0
How to Deploy the Improvement Kata v7.0How to Deploy the Improvement Kata v7.0
How to Deploy the Improvement Kata v7.0
 
Logic
LogicLogic
Logic
 
Introduction to the Improvement Kata
Introduction to the Improvement KataIntroduction to the Improvement Kata
Introduction to the Improvement Kata
 
Logic Ppt
Logic PptLogic Ppt
Logic Ppt
 
CONFLICT POWERPOINT
CONFLICT POWERPOINTCONFLICT POWERPOINT
CONFLICT POWERPOINT
 
Two Mindset Obstacles to Effective Learning
Two Mindset Obstacles to Effective LearningTwo Mindset Obstacles to Effective Learning
Two Mindset Obstacles to Effective Learning
 
Work Study: Method Study & Work Measurement
Work Study: Method Study & Work MeasurementWork Study: Method Study & Work Measurement
Work Study: Method Study & Work Measurement
 
Kata Slides & Graphics v4.1
Kata Slides & Graphics v4.1Kata Slides & Graphics v4.1
Kata Slides & Graphics v4.1
 
Training and development slides (2)
Training and development slides (2)Training and development slides (2)
Training and development slides (2)
 
10 performance and scalability secrets of ASP.NET websites
10 performance and scalability secrets of ASP.NET websites10 performance and scalability secrets of ASP.NET websites
10 performance and scalability secrets of ASP.NET websites
 
training & development ppt
training & development ppttraining & development ppt
training & development ppt
 
Factory’s act 1948
Factory’s act 1948Factory’s act 1948
Factory’s act 1948
 
Methods Of Training
Methods Of TrainingMethods Of Training
Methods Of Training
 
Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)
Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)
Stress At Work (Tips to Reduce and Manage Job and Workplace Stress)
 

Dernier

Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 

Dernier (20)

Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 

Worst Practices: Learning the Wrong Lessons from WikiLeaks

  • 1. 06350<br />Worst Practices: Learning the Wrong Lessons from WikiLeaks<br />By Sean Gallagher<br />Sean Gallagher covers defense and public sector IT, as well as general IT, for C4ISR Journal, Internet Evolution, Ziff Davis, and NBC Digital Networks, and consults on web and social media. He is the author of The Packet Rat blog.<br />The dark cloud of the WikiLeaks debacle should have a bright silver lining. The exposure of classified Department of Defense and State Department data by WikiLeaks gives us a teachable moment on information security — not just for government agencies, but for any organization that stores, handles, and processes sensitive information.<br />The vast amount of classified data — over 75,000 Defense Department incident reports and more than 115,000 classified diplomatic cables — and the damage caused by their exposure reveals common flaws in how organizations typically handle sensitive information. But as with past data breaches, many organizations will learn the wrong lessons. And the actions they take as a result will make their organizations less productive and, perhaps, even less secure.<br />They’ll severely curtail information sharing within and between their organizations. They’ll put “additional safeguards” in place to prevent insiders from exposing sensitive data. They’ll do more briefcase checks, tighten password policies, and perform internal paper audits of policy compliance.<br />These knee-jerk responses to an event such as WikiLeaks aren’t best security practices in any sense of the word. Instead of simply putting more locks on more doors, organizations need to start with two things:<br />Find and fix the fundamental problems in how their workflow around sensitive data is regulated and monitored.<br />Find and fix the fundamental problems in how existing security policies are applied and enforced.<br />With the benefit of retrospect, we now have a foundation that can help prevent the next WikiLeaks-style breach.<br />Reduce network complexity to apply security policies consistently.<br />Many of the problems that made the WikiLeaks exploit possible were issues already being addressed by the DoD before the breach occurred. But because of the magnitude and heterogeneity of DoD’s networks, consistent implementation of security policies has proven difficult. Organizations can dramatically reduce security risks — even those posed by insider threats — by simplifying the physical complexity of their networks, and by reducing the number of supported configurations of systems they need to manage.<br />Use role-based access instead of clearance-level access and “communities of interest.”<br />The alleged WikiLeaks source reportedly was astonished by the “so broad and yet so rich” data set that was made available to him. He was an intelligence analyst with a unit in Iraq, yet much of the data he is alleged to have pinched — including State Department cables regarding diplomatic relationships with countries outside the region — were irrelevant to his role, despite his Top Secret/ SCI clearance. Even if some parts of the data he was working with were relevant to his role as an intelligence analyst in Iraq, there’s no conceivable reason that one analyst should have access to every document classified “Secret.” Likewise, there’s no reason for a business analyst to have access to customers’ credit card numbers when evaluating purchase patterns. In cases where there are legitimate needs for data across roles, organizations should put strict governance over auditing and continuous monitoring. Indeed, had the DoD compartmentalized information into VPNs (virtual private networks) within the secure network, the WikiLeaker’s alleged access could have been curtailed. Collaboration outside of specific geographic or operational areas of interest would not have been possible. By allowing collaboration with people actually working with data, and excluding them when their assigned tasks don’t include work with the data, the risk of a WikiLeaks-scale exposure is markedly diminished.<br />Continuously monitor information access.<br />Having an audit trail of who accesses what information when is not alone sufficient to prevent data breaches. It’s like an idiot light on a dashboard: It glows red after something happened. Organizations need to monitor what’s being done with data, and alert on behaviors that fall outside the norm. Data loss prevention (DLP) software can automate some of this monitoring. It can flag unusual volumes or types of data access by users, and prevent the transfer of metadata-tagged content from the network.<br />Control removable media.<br />DoD officials say the data exposed by WikiLeaks was downloaded to optical disks from a computer connected to the DoD’s Secret Internet Protocol Router Network (SIPRNet). In December, the DoD reinstated a ban against using removable media with classified systems, after dropping a ban that had been imposed after a 2008 malware attack on SIPRNet. Removable media can be locked down automatically through a number of security policy enforcement tools.<br />These steps only work if they’re consistently applied across the enterprise, constantly refined, and consistently automated. Even the most rigorous security practices and policies fail if they’re static.<br />As Sanjeev “Sonny” Bhagowalia, Deputy Associate Administrator of the General Services Administration’s Office of Citizen Services and Innovative Technologies, recently said, “Compliance is a beautiful place to hide, but it doesn’t mean you’re secure.”<br />The more automated the implementation and adjustment of security measures are to users, the more effective they’ll be in the long term. And the more transparent those changes are to use, the less that they’ll adversely impact the organization’s mission in the process.<br />For more information visit www.unisys.com ©2011 Unisys Corporation. All rights reserved. Specifications are subject to change without notice. Unisys and the Unisys logo are registered trademarks of Unisys Corporation. All other brands and products referenced herein are acknowledged to be trademarks or registered trademarks of their respective holders. Printed in United States of AmericaMarch 2011<br />