The 4 Tiers of a Secure B2B Framework
Added 20th Jun 2010With new challenges ahead, it's useful to recognize the evolution of B2B security architecture in order to understand the future.
In the past, the perimeter was hardened with static controls. This architecture was suitable for static and known communication interfaces, and there wasn't much coordination between the appliances and the application layer.
Today, security controls get past the perimeter to service specific needs. Technologies span from perimeter to core applications, server farms, and databases that harden critical applications and data. The DMZ-based deployment is not replaced, but rather complemented with controls at critical demarcation points for applications and data. The security appliances are more identity-aware as they frequently communicate with backend infrastructure to enforce controls.
In the future, cloud-based services will complement application and data security, with the emergence of application and data controls in the cloud. Technologies such as antimalware, script analysis, URL filtering, IPS and web application firewall in the cloud will be high on the security professional's wish list for securing B2B transactions. At the same time, organizations will look to more distributed enforcement methods that require network and physical technologies to be still on-premises.
Moving forward, many of the traditional controls used to secure B2B interactions won't be adequate as major developments challenge the current security architecture. For example, it's not uncommon to have business transaction and interactions "on the go" with the use of mobile devices and interactive media using Web 2.0 apps. The dynamic nature of this content poses new threats that are specific to application and Web security.
Additionally, today's cloud offerings provide new ways to share applications with B2B partners. It's a compelling option that businesses can't ignore due to its scale, flexibility and cost structure. But as a security professional, it's your job to recognize the security and privacy concerns.
Smart Computing will also challenge today's security architecture. With the onset of Smart Grid and Smart City projects, businesses will have complex and pervasive partner relationships, some nontraditional in nature. This advancement will require security and risk assessment and management as the connected ecosystem increases cyberthreats and data confidentiality demands.
latest Articles
-
CIOs Don't Need to be Business Leaders
Given the complexity of today's applications, it's folly to suggest that the future role of the CIO is less technical and more businesslike, columnist Bernard Golden writes. If anything, it's the opposite -- the business side of the enterprise should embrace technology.
-
10 Steps to Business Process Transformation
Spurred by the recession, CIOs have sharpened their focus on processes, as companies strive for greater efficiency, and transformed business models, believes Coonie Moore Principal Analyst at Forrester Research.
-
Keeping IT Up
How IT business continuity is challenged by four tech megatrends: Social, mobile, virtualization and cloud.
-
5 Things I Have Learned: Alagu Balaraman
Alagu Balaraman, former CIO and current partner and MD India Operations at consultancy firm CGN & Associates, has spent 20 years doing different things and doing things differently.


