Wednesday, September 2, 2009

Security tools are cool.

Yes, there isn’t a problem that you can’t solve with a tool…at least from a Pre-Sale’s point of view. But you always hear about the decision dilemma and analysis that goes into purchasing a tool—and yes you’ll need to consider the IT/Business strategic, vendor longevity, supportability and manageability, and of course integration factor. Enough said, let’s just look at a cool solution as it stands today (because tomorrow, technology would have already changed)


Content and URL filtering: Go with Websense as the overall leader in this space and add a little BlueCoat for enforcement and you can’t go wrong (or just pure BlueCoat as competing best overall solution). Then, round out the top in this space with IronPort solution
Cloud did you say…go with Zscaler, they just seem to be everywhere

Firewall: Stick with Cisco overall but better trend setter is Juniper as well as CheckPoint R70—for creativity/vision (over Cisco).
And, related subset of tool check out Algosec then Tufin for management/audit

DLP: [industry beloved term -of-the-year] you’ll need to check out Websense again with Port Authority and joust with Symantec’s Vontu. But perhaps also a little HP if they can make Fortify work (or just buy them, right)

WAF: [another watercooler conversation] web and XML firewalls and for this go with Imperva or Breach but no strong push here….any thoughts here

IDS/IPS: [ever say die] Snort equals SourceFire so go with what works but if you believe the hype then go with Tipping Point and have it manage itself…hummmm

SIM/SEM/SIEM: [not forgotten] ArcSight because you have the $$$ to do so; followed by RSA because everyone has an RSA component otherwise look into LogLogic (proven) and Splunk (cheap/ease of use)

and yes the infamous NAC solution, I covered in a prior post