Whole Network Most Recent TOP10 CIO Outsourcing SaaS Security

 

Securing Google

Filed in archive Security by Scott Wilson on April 11, 2008

iStock_000000845368Smaller.jpg
It hadn't occured to me until I read this article that I have never heard of a security breach at Google. Sure, people game the search results system from time to time, but that's not the same thing; in fact, it's simply one end of a long sliding scale of SEO marketing efforts. No, I'm talking about honest to goodness, black-hat intrusions. Google has thousands of servers, hundreds of exposed services, and increasingly large numbers of staff to make passes at. You have to imagine they are attacked at least as frequently as any other sizeable corporation, which is very frequently... thousands of times a day in most cases. If they've managed to avoid having even a trivial penetration, that would be pretty impressive.

We don't know the exact numbers, of course, and Google is famously tight-lipped, but unless they are risking real disaster and legal action by covering up some incident, it sounds like their security is pretty good. A tantalizing article in Australia's IT News gives us a glimpse of what it takes to run a secure IT infrastructure on a massive scale.

It's not magic, unsurprisingly; speaking at RSA's security conference, Scott petrylinks of Google's recent mail-security acquisition Postini describes steps taken to create a culture of security: mandatory security training, stock security code libraries, inside and external code review. Although it wasn't mentioned, I also have to think that Google's "we'll release when we are ready" approach to project management also represents security as a cultural value; no compromises need be made to meet a ship date. Getting the code right takes precedence over getting it to market.

There are important lessons there not just for coders, but for any IT organization. Too often I see CIOs or other executives who go out and buy the shiny security software of the day, or hire a top-flight security consultant, and expect that step to make their organization secure. The reality is that security has to be a cultural value in order to be effective; the bad guy only has to get it right once, the CIO has to get it right every time. You can't do that if not everyone in your organization and supply chain has a commitment to being secure.


Advertisement


Permalink: Securing Google
Tags: Google  code  culture  google  security  securing+google  open+source  advertisement+book 

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/119937



Related Entries:

Google Code Jam contest 2006赛果揭晓 - 10 四月 2006

Google Code Jam 2006赛果揭晓 - 29 十月 2006

Google Code Jam... - 07 十一月 2006

Open-Source-Code finden - 04 Juni 2007

Advertisement


Advertisement


CW ToolbarInstall
RSSrss   | See all blog subscribe options
Googlegoogle   |   What is RSS?
Yahoo!yahoo
AddthisAddThis Feed Button
BloglinesBloglines
Newsletter
Advertisement - Book yours here.

Use our search feature to look for other interesting posts

Just this blog Whole network
 
Advertisement
Book yours here.



  • Testimonials

  • 'I don't really think you should keep testimonials from the last guy here, do you?'
  • Other blogs in the same channel in the Creative Weblogging Network

Advertisement -
Book yours here..






Advertisement - Book yours here..
 
Tagcloud: CIO Data Storage Enterprise Hardware Enterprise Software Events General Help Desk And Support Integration Software Management Market Perturbations Networking Offshoring Outsourcing SaaS Security SOA Sponsored Posts The Cloud The Vision Thing Virtualization