Home > Financial Services Information Security Tips > Security Architecture Insider > Integrating firewalls into your financial enterprise systems
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

Integrating firewalls into your financial enterprise systems


Judith Myerson, Contributor
09.17.2008
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


To better protect your financial enterprise system, you have firewalls in many areas of a network topology, mostly found guarding the perimeters of your networks. The reality is that is not enough.

Today's firewall technologies are getting more complex and harder to configure and administer. Technologies, such as virtual private networks (VPNs) and wireless networking, make maintaining this perimeter more difficult.

For this reason, the firewall technologies might operate in an unexpected way that could cause unplanned network downtimes and ultimately a system crash. To get the firewalls to work at an optimum, you need to integrate a firewall management policy into your system.

When implementing the firewall management policy, the ultimate goal is to quickly bolster security, support a larger IT policy as well as provide detailed guidance for the people managing the firewalls. To achieve this, financial services firm should do the following steps.

  • Conduct an economic feasibility study of installing and integrating firewall and perimeters technologies into the financial enterprise system. The study should include system challenges such as security, logistical, scalability, operation, IT, program management and education and training.
  • Conduct a site analysis to ensure firewall and perimeter management can be integrated with the system and your existing architecture of hosts, users, servers and other elements of the network. The analysis should include the capacity, expandability, scalability and management of firewalls and perimeters.
  • Review your firewall management policies to ensure they are keeping pace with new threats (e.g., via firewalls logs) and does not conflict with established security and business policies. Review firewall configurations in response to changes to compliance regulations.
  • Review your compliance policies to ensure the

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Security Architecture Insider
    Winning the war: Personal information protection
    Why financials must implement Web application security best practices
    Identity management for financial firms in turbulent times
    Identity management for financial firms in turbulent times
    How to use data loss prevention tools to stop data exfiltration
    Security questions to ask SaaS vendors when outsourcing services
    Book chapter: Remote deposit capture risks
    How to communicate the value of security controls for online transactions
    How to perform a network device audit
    Emerging themes in identity access management

    Network security devices for financial institutions
    Organization aims to develop encryption standard for card data
    How to use data loss prevention tools to stop data exfiltration
    How to perform a network device audit
    Event data analysis
    Security on the street with SearchFinancialSecurity.com: Mobile banking
    Don't let fads dictate your network security strategy
    How to easily integrate managed email security services
    How to integrate network behavior anomaly detection into enterprise systems
    How to get the most out of a SIM
    Top NAC challenges include cost, interoperability issues

    VPNs and secure remote access for financial institutions
    Steps to secure your remote users
    Top NAC challenges include cost, interoperability issues
    New remote access system cuts costs
    Disaster recovery, security drive financial firm to Private IP
    SSL VPN use is all about security
    How remote access control products affect Windows file permissions

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    compliance regulations have been met and the data required for compliance has not been blocked by the firewalls and the storage of data has been retained for a specified period of time. Review your backup policies and test periodically the restoration of backup media. Run backup tapes at off-production times to ensure they are in good condition.

  • Conduct a pilot study on integrating firewall management policy into a sample portion of the enterprise. This will help the integrators solve any potential problems before integrating the firewalls on a large scale, as well as determine what education and training the systems administrators will need to solve unusual anomalies. Without proper training and education, the firewalls can be difficult to configure and administrator.
  • As part of the study, test stateful multi-level (SML) firewalls to see if they deploy the best features of the other three firewall types: network, circuit and application levels. They filter packets at the network level and they recognize and process application-level data. They don't employ proxies, but they deliver reasonably good performance in spite of the deep packet analysis.
  • Test firewall monitoring for real-time alerting and consider using an add-on product to combat emerging threats. Periodically test new technologies against the firewall to determine that the system is performing as designed. Review firewall logs.
  • Implementing the firewall management policy can be a challenge for a financial services firm. Proper implementation techniques can make the job easier.

    About the author:
    Judith M. Myerson is a systems architect and engineer. Her areas of interest include middleware technologies, enterprise-wide system, database technologies, application development, network management, computer security, information assurance, financial, RFID technologies and project management.


    Rate this Tip
    To rate tips, you must be a member of SearchFinancialSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts