I travel a lot internationally and I can’t but help notice the vast differences in airport security procedures.
Some airports perform a security scan of you and your luggage before you can even get to the check-in counters. Some perform a security scan after you pick up your luggage in baggage claim before you exit the airport. Some perform a security scan at the gate before you board and after you have already been through 2 previous security scans!
Then there is the whole inconsistent rigmarole of what you can take in your carry-on. Some allow water and liquids over 100 ml, some don’t. Some make you remove all your electronics, some don’t. Some don’t allow metal straws; some don’t allow power adaptors.
Finally, there is the personal scan which often turns the security area into a football changing room. Removing shoes, belts, jackets, hoodies, watches, paper tissues in your pocket and, again, no consistency. Some airport security will still perform a secondary body search even after you’ve removed half your attire and you passed through the scan cleanly!
You now need at least 3 hours before your flight to accommodate for these security checks on international flights and the cost and labor required has made travel more expensive, confusing and stressful.
We have become obsessed with security yet, every day, people pass through these checks taking items that are not allowed and not detected.
Computer applications and data has followed the same path. Most organizations have set up entire data security teams who use a variety of monitoring tools, virus scan software, penetration tests, security audits and procedures to minimize unauthorized access to data and applications.
Yet, here too, there is the same inconsistency as at international airports. It is rare to find organizations using the same set of virus scan software tools and none of them are foolproof. Many even cause system outages and I’m not just talking about the recent Crowdstrike incident. Virus scan software will often delete critical files during a software installation or upgrade process (including BusinessObjects) causing it to fail. The files and directories of so much software now needs to be white-listed that these lists are sometimes bigger than the black-lists! Worse still, is when the virus scan software interferes with files when the software is running mission-critical applications – and, yes, it happens more frequently than you may think.
Many organizations now require 30+ page audit questionnaires to be filled out and then reviewed not just for new software but for existing software they have been running for years. In addition, they require security certifications (many different types and standards here) and a review process that sometimes take months going back and forth with the software provider.
Then there is the whole area of user access which has the same similarities and inconsistencies as walking through those security scanners at the airport. A process to get someone access to an application or data now takes days or weeks instead of hours. In times of urgent need (e.g. application running slow or down) or frustration, many I.T. groups will just bypass the security process by setting up a remote desktop or web meeting for the person needing access.
Some companies thought they could shift the responsibility of security to cloud providers by moving their applications and data to the Cloud only to find out that the Cloud providers will not take on that liability and so you still need your own Security group to oversee that too.
We all understand the need for security, but the amount of money most organizations now spend on data/application security coupled with the cost in delays to almost every part of the business is accelerating with no end in sight.
I know many CIO’s who share the same concern. Security is important but maybe it needs to be rationalized and brought into perspective in terms of the rest of the business.
Almost all commodity applications, including BusinessObjects, have a wide range of security controls at all levels to meet most security needs. Once the security requirements are understood, there will usually be several options as to how they can be implemented. This is the time to engage an expert familiar with that applications security options to help both configure the best solution and provide knowledge transfer to maintain it in house.
Security has become the “elephant in the room” for a lot of organizations today but the best way to eat an elephant is a bite at a time.
