Showing posts with label emergency preparedness. Show all posts
Showing posts with label emergency preparedness. Show all posts

Monday, June 18, 2012

The Exec-Disconnect on IT Security

Different Chiefs give Different Security Stories.

A recent survey shows that there is a wide gap between CEOs and Chief Security Officers when it comes to the origin and seriousness of security threats.  They differ on how they view threats to IT Infrastructure  and remain far apart on how to best address an issue that according to analyst reports, costs organizations more than $30 billion annually.  The survey of 100 CEOs and 100 CISO (or other C-levels with security responsibility), shows that the discrepancy is often due to lack of communication.  36% of CEOs said that they never get a security report from their CISO and only 27% receive updates on a regular basis.  Is it the CISO that doesn’t report back or the CEO that is not interested?  Let’s look at some more data.

The CISO felt that the biggest threat was from internal (their employees) due to lack of education and attention while the CEO felt that the biggest threat was from the outside, such as phishing attacks.   Thus, 61% of CEOs said they did have enough time and resources to adequately train the staff on how to mitigate threats while Only 27% of CISOs felt the same.  It’s opposite day.  When asked if their IT systems were ‘definitely’ or ‘probably’ under attack without their knowledge, 58% of CISOs said yes while only 26% of CEOs agreeing.  The chasm grows.  What percentage of each, do you think, said they were very concerned about their IT systems getting hacked?  30 seconds on the clock, please.  Don’t peek.  Only 15% of CEOs and ‘only’ 62% of CISOs are anxious about breaches.  15%?  That’s it?  Maybe they have great confidence in their security team…or, they don’t have the information.  65% of CEOs admitted to not having the sufficient data needed to interpret how security threats translate to overall business risk.  Wow, the very day-to-day operations.  Granted, the CEO is further removed from the specific threats and how they are handled but there is clearly a distance between how each views threats and the company’s ability to successfully mitigate them.

Lack of interest or lack of understanding/information?  Probably both.  An old adage was that a great boss hired people who were good at the things he/she wasn’t so good at.  Surround yourself with those who know their areas better.  Or maybe there is a culture that you don’t alert the top unless it’s dire, critical or unstoppable.   Communication or interest, it is evident that the C-suite isn’t really talking about these critical business issues especially when 3 times as many CEOs worried about losing their jobs following an attack than did CISOs.

ps

References

Technorati Tags: F5, security research, botnet, threat landscape, Pete Silva, security, business, technology, cloud,compliance,regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, January 17, 2012

Security’s Rough Ride

1 if by land, 2 of by sea, 0 if by IP

I know I’ve said this before but it sure seems like almost daily there is a security breach somewhere.  Over the years, the thought process has changed from prevent all attacks to, it is inevitable that we will be breached.  The massive number of attacks occurring daily makes it a statistical reality.  Now organizations are looking for the right solution (both technology and practice) to quickly detect a breach, stop it, identify what occurred and what data may have been compromised.  Over the last couple of days various entities have had their security breached.

As you are probably already aware either due to the headlines or a direct note in your email inbox, Zappos, a popular online shoe site, was compromised exposing information on 24 million customers.  While a good bit of info was taken, like usernames, passwords, addresses, email and other identifiable information, Zappos claims that the stored credit card information was apparently spared due to being encrypted.  There are still many details that are unknown like how it occurred and how long it had been exposed but all users are being required to change their passwords immediately.  Users might also want to change similar passwords on other websites since I’m sure the criminals are already trying those stolen passwords around the web.  These days it's entirely too easy to use information from one hack in many others.  It doesn't even matter if passwords were compromised.  Your can change your password, but the make and model of your first car, and your mother's maiden name can't be changed.  Yet, online service providers continue to rely on these relatively weak forms of secondary authentication.  The interesting thing is Zappos is/was apparently PCI-DSS compliant, proving once again, PCI compliance is a first step, not the goal.  Being PCI compliance does not mean that one is secure and this also underscores importance of using WAF like BIG-IP ASM.  And if it was not a web app that was owned on the server in Kentucky, then Section 6.6 is irrelevant.  But again, all the details are still to be uncovered and as far as I know, no-one has claimed responsibility.

Overseas, there is an ongoing cyber-war between a Saudi (reported) hacker and Israel.  0xOmar, as news articles have identified him, claims to have posted details of 400,000 Israeli-owned credit cards and Israel’s main credit card companies have admitted that 20,000 cards have been exposed.  Along the way, he has also attacked the Tel Aviv Stock Exchange and Bank Massad.  In an interesting and potentially scary turn of events, a group of Israeli hackers, IDF-Team, took down the Saudi Stock Exchange (Tadawul) and the Abu Dhabi Securities Exchange (ADX) as a counter-attack.  Another Israeli hacker going by Hannibal claims to have 30 million Arab e-mail addresses, complete with passwords (including Facebook passwords), and says he’s received e-mails not only from potential victims but from officials in France and other countries asking him to stop.  This cyber-conflict is escalating.

In a very different type of breach, you’ve probably also seen the cruise ship laying on it’s side a mere 200 yards from the Italian shore.  While not necessarily a data security story, it is still a human security story that, so far, has been attributed to human error – like many data security breaches.  Like many data breach victims, people put their trust in another entity.  Their internal risk-analysis tells them that it is relatively safe and the probability of disaster is low.  But when people make bad decisions which seems the case in this situation, many others are put at greater risk.

Put on your virtual life vests, 2012 is gonna be a ride.

ps

References:

Technorati Tags: F5, cyber-crime, trojan, Pete Silva, security, business, education, technology, application delivery, cruise, cyber war, ddos, hackers, iPhone, web, internet, security, breach, privacy, PCI-DSS,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, November 2, 2011

When Personal Security is Compromised

My Greatest Fears Realized

I debated about writing and/or blogging about this for a few days since it is very personal and didn’t want a pity-party coming my way.  But covering security, often from the human behavior standpoint, is what I do and what better way to share a security incident than when it happens directly to you.  Plus, being able to simply get it out is cathartic to some extent.  So here goes.

I attended the London IPExpo on Oct 19-20 at Earl's Court Two.  IPExpo is one of the largest IT infrastructure shows in Europe with many focus areas: Cloud, Storage, Security, Network, Virtualization and so forth - pretty much anything that touches IT.  I was invited by the F5 EMEA team to present at a number of speaking sessions F5 offered during the conference.  I also brought my family along since we hadn’t been to London in about 5 years and we really like the city. 

A couple weeks ago while I was at work at our EMEA headquarters there was an attempted abduction/kidnapping of my 5 year old daughter at one of the underground stations in London. My wife and daughter were on their way shopping when a man grabbed her.  He started with a little lure and when they got closer, he grabbed her arm and tried to yank her away from my wife.  Luckily my wife was able to keep hold of her and said to another woman, ‘Did you see what that guy just did to my daughter?’  She responded with, ‘yes and it looks like he’s doing it to another little girl!’  At that point, my wife asked for assistance from the Underground personnel.  The BTP (British Transportation Police) arrived and took him into custody while taking my wife and daughter to the station for statements.  My daughter asked if she could tell the officer about what happened and she told the PC, ‘that man grabbed my arm.’  That was pretty much all they needed, especially after viewing the CCTV footage and they didn't want to pressure a grueling interview of a child. 

I was finishing lunch with an F5 colleague when I got the call – ‘we are at the police station and you need to come now.’  At first I wasn’t sure if she was joking since she’s used that ‘I’m at the cop-shop’ routine before and I said, ‘What?!?, are you kidding?’  She then briefly told me about the incident, that he was in custody and at that point, it was no joke and my personal security had been threatened.  My co-worker immediately said, ‘I’ll take you wherever you need to go.’  This is one of the things that I love about my working family at F5, personal family is always first.  That was when the flood of emotions overcame me and the gravity of the situation hit.  As an aside, I don’t worry about my family going anywhere since my wife is a former Federal Law Enforcement Agent and certainly knows how to handle such situations.

I often look at human behavior and the ‘feeling of security’ or ‘peace of mind’ when discussing the topic.  I think that many of the fears about say, cloud security or any other topic that seems to take a few years to fully catch-on, has to do with the fact that we humans simply have a hard time with change.  Add loss of control to the picture makes it even more daunting.  Friends will say, ‘Let it go, it’s out of your control,’ and while you may understand, it doesn’t always make you feel any better.  That day, I did not have a feeling of security, peace of mind or any control over the situation.  I knew they were safe but I did not feel safe.  The mind kept telling the belly ‘it’s OK.’ but the gut wasn’t listening.  The stress increases, it’s harder to think, you’re sweating and it’s uncomfortable. 

Finally arriving at the station, the Sergeant tells me everyone is fine, the guy is arrested and we’ll let your family know you are here.  Some anxiety is finally released and soon, we get to hug.  More stress leaves the body and thinking becomes more focused but still has plenty of questions.  The BTP was great and gave us a ride in the blue and white back to our hotel. We were told on the way back that he is well known within the police department and a repeat offender.  Not sure if that was good or bad news.

The following day, the BTP called and said that the guy is being charged with assault (of a minor).  The CCTV caught everything.  Now, I’m not a big fan of the increased surveillance everywhere but in this situation it helped tremendously.  The next day it was determined that he needed a psychiatric evaluation and spent the next week in the mental facility.  My wife was also asked to appear for his trial, which was scheduled for the following week.  Wow, right quick as they fast tracked his trial.

My wife was at the Magistrates' Court most of the day.  After a week in the mental hospital, one doc called him crazy and another said he was fit.  That obviously determines which institution will be his new home. The judge had already watched the CCTV, received testimony from the responding officers, including the one who testified on my daughter's behalf and my wife's testimony only lasted about 10-15 minutes.  The Magistrate just wanted to hear if her story matched what was on the video and other witness statements. His lawyer tried to make it seem like he was just being 'friendly.'  She was let go after her testimony for the final determination.

Later that evening we got a call and was told he had been found Guilty of assaulting a minor.  We dropped a huge sigh of relief and the flow of comfort came back again.  I was starting to feel secure again, I started to feel somewhat in control again and I could think clearly once more.  I believe we all go through stages when trying to make a security decision or faced with a security situation.  It’s called Risk Analysis, Risk Management and Emergency Preparedness.  This was an extreme case, of course, but the threat came unannounced from the outside like many that occur within the corporate infrastructure.  My wife was prepared and I was uncomfortable yet, we still needed to handle the situation and mitigate the risk.  With your corporate infrastructure, be prepared, have a plan, mitigate risk and you will feel secure and know that you are.  And if an incident does arise, you’ll be ready.  Find that common ground between the head and the heart.  Often that’s hard when various groups have different fears and things that make them uncomfortable.  Acknowledge the human factor, ask questions and communicate. 

I truly appreciated the F5 support and warm wishes during this ordeal.  I’ve been with F5 since 2004 and while we recently announced that we’ve passed $1 Billion in revenue, which is an amazing financial accomplishment but I have to tell you that it is the feeling of family that keeps F5 rolling.

ps

Technorati Tags: F5, personal security, police, london, Pete Silva, security, BTP, vulnerabilities, crime, child, CCTV, the tube, abduction, identity theft

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, September 21, 2010

Wednesday, May 5, 2010

CloudFucius Ponders: High-Availability in the Cloud

Konfuzius-1770 According to Gartner, “By 2012, 20 percent of businesses will own no IT assets.”  While the need for hardware will not disappear completely, hardware ownership is going through a transition: Virtualization, total cost of ownership (TCO) benefits, an openness to allow users run their personal machines on corporate networks, and the advent of cloud computing are all driving the movement to reduce hardware assets.  Cloud computing offers the ability to deliver critical business applications, systems, and services around the world with a high degree of availability, which enables a more productive workforce.  No matter which cloud service — IaaS, PaaS, or SaaS (or combination thereof) — a customer or service provider chooses, the availability of that service to users is paramount, especially if service level agreements (SLAs) are part of the contract.  Even with a huge cost savings, there is no benefit for either the user or business if an application or infrastructure component is unavailable or slow.

As hype about the cloud has turned into the opportunity for cost savings, operational efficiency, and IT agility, organizations are discussing, testing, and deploying some form of cloud computing.  Many IT departments initially moved to the cloud with non-critical applications and, after experiencing positive results and watching cloud computing quickly mature, are starting to move their business critical applications, enabling business units and IT departments to focus on the services and workflows that best serve the business.  Since the driver for any cloud deployment, regardless of model or location, is to deliver applications in the most efficient, agile, and secure way possible, the dynamic control plane of cloud architecture requires the capability to intercept, interpret, and instruct where the data must go and must have the necessary infrastructure, at strategic points of control, to enable quick, intelligent decisions and ensure consistent availability.

The on-demand, elastic, scalable, and customizable nature of the cloud must be considered when deploying cloud architectures.  Many different customers might be accessing the same back-end applications, but each customer has the expectation that only their application will be properly delivered to users.  Making sure that multiple instances of the same application are delivered in a scalable manner requires both load balancing and some form of server virtualization. An Application Delivery Controller (ADC) can virtualize back-end systems and can integrate deeply with the network and application servers to ensure the highest availability of a requested resource.  Each request is inspected using any number of metrics and then routed to the best available server.  Knowing how an ADC can enhance your application delivery architecture is essential prior to deployment. Many applications have stellar performance during the testing phase, only to fall apart when they are live. By adding a Virtual ADC to your development infrastructure, you can build, test and deploy your code with ADC enhancements from the start.

With an ADC, load balancing is just the foundation of what can be accomplished.  In application delivery architectures, additional elements such as caching, compression, rate shaping, authentication, and other customizable functionality, can be combined to provide a rich, agile, secure and highly available cloud infrastructure.  Scalability is also important in the cloud and being able to bring up or take down application instances seamlessly — as needed and without IT intervention — helps to prevent unnecessary costs if you’ve contracted a “pay as you go” cloud model.  An ADC can also isolate management and configuration functions to control cloud infrastructure access and keep network traffic separate to ensure segregation of customer environments and the security of the information.  The ability of an ADC to recognize network and application conditions contextually in real-time, as well as its ability to determine the best resource to deliver the request, ensures the availability of applications delivered from the cloud.

Availability is crucial; however, unless applications in the cloud are delivered without delay, especially when traveling over latency-sensitive connections, users will be frustrated waiting for “available” resources.  Additional cloud deployment scenarios like disaster recovery or seasonal web traffic surges might require a global server load balancer added to the architecture.  A Global ADC uses application awareness, geolocation, and network condition information to route requests to the cloud infrastructure that will respond best and using the geolocation of users based on IP address, you can route the user to the closest cloud or data center.  In extreme situations, such as a data center outage, a Global ADC will already know if a user’s primary location is unavailable and it will automatically route the user to the responding location.

Cloud computing, while still evolving in all its iterations, can offer IT a powerful alternative for efficient application, infrastructure, and platform delivery.  As businesses continue to embrace the cloud as an advantageous application delivery option, the basics are still the same: scalability, flexibility, and availability to enable a more agile infrastructure, faster time-to-market, a more productive workforce, and a lower TCO along with happier users.

And one from Confucius: The man of virtue makes the difficulty to be overcome his first business, and success only a subsequent consideration.

ps

The CloudFucius Series: Intro, 1, 2, 3

Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Thursday, April 29, 2010

Oracle Data Guard sync over the WAN with F5 BIG-IP

While at Interop 2010 this week, we shot some videos and in this one, learn how F5's WAN Optimization can enhance Oracle's Data Guard solution. I talk with Chris Akker, Solution Engineer, about the challenges of real-time database sync and Zero Data Loss over a Wide Area Network. Watch how F5's WAN Optimization can reduce latency, extend the distance required between data-centers and enable an enhanced disaster recovery solution.

ps

Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

Digg This

Wednesday, December 16, 2009

Catch some Zzzzzzzzzzzzz


It used to be the ‘stuck to our side’ pagers that go off at 3am telling you that a server crashed that would keep you up at night.  You’d drag yourself out of bed (or the chair at the data center that you fell asleep in), tippy-toe to the computer in hopes of gaining remote access or wonder to the car, still in your PJs, to drive to the facility.  In February 2009, InformationWeek & Dark Reading conducted a survey entitled, ‘What Keeps Infosec Pros Awake at Night.’  They asked more than 400 IT pros, among other things, what are their most serious threats, how are they prioritizing their defense of these and what are they going to do to keep their data safe in 2009 and beyond.  At the time, 52% said they were concerned about Internal threats – either employees or partners, accidental or malicious.  This makes sense since there were several articles in early 2009 which looked at Laid-off workers turning to Cybercrime.  They also feared the loss/theft of a laptop/potable storage device which might contain sensitive information that can lead to a corporate security breach.  Their biggest wish was for end users to be smarter about security and understand the risks.  Automated technology allowing IT pros to focus on emerging threats rather than day-to-day firefighting came in 2nd.  They just wanted to have the time to find ways to make their systems more secure, and compliance was driving it.

Recent data from Verizon’s addendum to its Data Breach Investigations Report actually shows that most (73%) data breaches come from External sources, not insiders.  Granted, the InformationWeek data was garnered from a survey (point in time opinion) and the Verizon info was generated by analyzing disclosed/investigated public data breaches (over time) and it doesn’t include undisclosed incidents with internal investigations.  Verizon concluded that breaches which warranted public disclosure were primarily done by external sources.  I’m sure that many internal incidents that didn't affect a large swath of the public were never disclosed, which could slightly sway the results but interesting nonetheless.  So the fear was Insider threats yet the actual data implicates outsiders.  I started wondering if this one of those Perception vs. Reality things or as Stephen Covey puts it, “We see the world, not as it is, but as we are.” 

In February 2009, when the economic crisis was in full swing, layoffs were a daily occurrence.  There were many documented cases in the early 1990’s of crime/fraud that occurred during that recession and many believed it would happen again – but this time with technology's help.  Stories started to appear indicating that this scenario might happen again and when the few that did happen were spotlighted (like the current trial of Terry Childs) - folks believed, or feared, that a new wave was coming.  The data that came out other end, seems to show that those internal threats were less than expected, except maybe in the financial industry.  The other side is that sometimes perception is more important than reality.  With the perceived immanent danger of rogue ex-employees, IT departments had a wake up call to reexamine how they handle access termination, a critical piece of data preservation.  In life and security, our view of the perceived risk is based on our past experiences/beliefs and that ultimately shapes our reality.  My reality and your reality might be very different but we always have the power in how we respond to events, even ones out of your control.  So as 2009 winds down and you get some needed rest (maybe), revel in the fact that this challenging year is almost over, you did the best (hopefully) you could and there will be a whole new set of threats, breaches, viruses, vulnerabilities, scams, malware and many other incidents that put security at risk as thieves typically work through the holidays.  Plan as best you can and take the new ones in stride as a challenge to all of us to get even better at protecting all our critical assets – including the living, breathing ones.

And there you have it – 26 Short Topics about Security.  Yea, we made it!  But wait, there’s more.  Stay tuned for the Post-blog Report where we look back at the series, pick some favorites and share what I’ve learned about putting together a chain of blogs over the course of 5 months covering a single topic.  Should be fun.

ps

Technorati Tags: Pete Silva,F5,security,application security,network security,virus,

Monday, December 14, 2009

It all comes down to YOU - The User



One of my favorite Security writers, Bruce Schneier, had an interesting entry last week called Reacting to Security Vulnerabilities where he discusses the recent reports about the security flaw in the SSL protocol and how we as users should relax and essentially, ‘do nothing.’  “What?!? – Do nothing??”  Yup, and he has some good reasons why.  Usually, new exploits, threats, breaches and the typical security stuff that garners the headlines, makes security folks jump.  Jump to search the internet for anything related, jump to see if our systems are infected or vulnerable, jump to put an action plan in place to reduce the risk.  These are reactionary behaviors when gloom gets delivered and we fully don’t understand the risk.  I’m not saying ignore warnings or plan for the worst, but since several new ‘weaknesses’ seem to get published on a monthly basis, you do need to prioritize and put some context around it.

With anything in life, there are certain things we have control over and others we do not.  For many years now, we’ve been warned that it is risky to click on embedded links in a suspicious email or dangerous to click through the certificate warnings from your browser and hopefully many people have changed their behavior.  That’s within our control.  But when a researcher finds a specific vulnerability in a particular protocol, potentially affecting several vendors, there is really not much an individual user can do.  Sure, you or the IT department can check with their vendor to see if it applies to their product but would you immediately stop using something when it’s a critical part of your infrastructure.  Once again, which is usually the case for security, you must weigh the risks and determine if it’s within your control.  Bruce points out that many of the vulnerabilities affect systems that are out of our control and if your data is already out there, unplugging your computer will not lessen the potential exposure.

What you can do is simply stick to your general security practices (AV/FW, OS patch, Auto updates, backups, common sense), which already protect you from a slew vulnerabilities but let the experts/vendors figure out the best way to handle new exposure(s) since they must deal with them on a daily basis.  If the risk is too great and your infrastructure is vulnerable, push your vendor for an answer.  Most vendors, especially with security products, are fairly reasonable and typically move fast when it comes to security holes – their reputation and revenue are at risk.  You can also report to CERT if you’re not getting a response but most vulnerability ‘finders’ alert the vendor fist and give them a chance to fix or respond to it.

Protecting yourself from the multitude of threats on the internet can be daunting, never ending, and always changing so you do need to be vigilant with the things you can control but as you peruse the Top 9 Beaches of 2009 or the Top 15 Most Common Attacks, you find there was/is little you could do to avoid them.
ps

*For the record, F5 is listed on the US-CERT site as being potentially vulnerable but we have tested our products/versions and are not vulnerable to this issue.  F5 Networks has published a security advisory in the past to cover similar vulnerability and provide best practice recommendations. These best practice recommendations can be found at the F5 support site:
https://support.f5.com/kb/en-us/solutions/public/6000/900/sol6999.html
https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html 

Friday, November 6, 2009

IPv6 and the End of the World

There’s always been a certain amount of conspiracy theories when security type events happen or instances where there is secrecy. There are those who don’t buy the ‘reported’ reason a security event (like a breach) occurred, those who claim to have inside information or just those who see a story and draw their own conclusions. The following is my take (Satire Alert) on Transmission Control Protocol/Internet Protocol v6 and the end of the world as we know it. That can affect our security, right?!?

Recently there have been more than the usual number of articles about IPv6 and the need to deploy it soon since the v4 blocks are almost gone. Yes we’ve been hearing this for years (RFC2460 was defined in December 1998) but now the hype may be over as indicated in this article. There are many security enhancements in v6 nicely covered here but that’s not where I’m going.

In my first blog post on DevCentral, aptly titled First Post, I introduced psilva’s prophecies. I’ve been in the Internet industry since ’94 and while not a ‘know it all’ I have seen my share of changes and have seen a bunch of ‘ideas’ over time come true. For instance, I had always thought that the Internet would eventually become our entertainment delivery method and some 14 years later, that’s the case. That’s not that wild as I’m sure many of you figured it was only a matter of time once we started to see streaming video and broadband to the home. In that First Post, I offered my prediction of how our nomenclature might change over the next 50-100 years. That now, we no longer give our full name/address for contacting/correspondence as we’ve done in the past – we just give email. The idea was that over time, our current first/last naming convention might dissolve to where we are known as users@domains or a single string of characters. Twitter is enforcing that with their @namingconventions.

IPv6, at 128-bits (v4 is 32-bit), gives us the ability to assign an IP address to just about anything – heck, all the portable mobile devices we carry each need one and consumer appliances like TVs, refrigerators, thermostat, DVRs, garage door openers, coffee machines and just about any electronic item could potentially have an IP address. Schedule your toaster via a Web GUI to perfectly brown your bagel when you get home. You can already control your lights and alarm systems over the internet. In addition, each one of us, worldwide, would be able to have our own personal IP address that would follow us anywhere.  Hold on, I’m getting a call through my earring but first must authenticate with the chip in my earlobe. That same chip, after checking my print and pulse, would open the garage, unlock the doors, disable the home alarm, turn on the heat and start the microwave for a nice hot meal as soon as I enter. I could chip my child (like the dog) to be able to GPS their behind if they are not at the movies as indicated. Not so farfetched. That doesn’t sound so sinister, psilva, how can that be the beginning of the end?


OK, now the fun begins.  While not a Nostradamus follower, although  History/Discovery Channels have covered him often, he does have something to say about numbers. You might remember he got a lot of press and was the subject of spam after 9/11 due to this quatrain which his followers say indicates that he predicted that disaster. Conspiracy? He was very much into numbers and also indicated that when we are all identified as numbers, that will be an sign of the impending doom. We do have a numbering system in the states called a Social Security Number, which is our Gov’t identity and very much linked to our own security. With IPv6, now the entire world can be identified by number and thus fulfills psilva’s prophecy #2.  The timing is right also.  2012 is getting a lot of play as the end of time.  Both the Mayans and Nostradamus feel that 2012 is the end of days and Hollywood has taken notice.  Now this does slightly negate my 1st prophecy since I’m giving our name change around 50 years but 2012 does sound about right for a full IPv6 transformation so it does fit nicely with doomsayers – if you’re into conspiracies.

ps

Friday, September 25, 2009

Our H1N1 Preparedness Plan

On a couple occasions, I have  have offered advice on how to deal with disasters and just yesterday I wrote about Mitigating risks.  Today, I’m deviating slightly from 26 Short – make this #13.5 – to share some of F5’s Emergency Preparedness plans for the possible resurgence of H1N1.  While we often try to give interesting tips, ideas and suggestions to help you and since many of you might be going thru the same exercise, I though I’d share how we are preparing ourselves.  Per usual, this is not to flame the fears already in the media but offer calming assurance that there is no reason to panic.
F5’s main objectives for Emergency Preparedness for Employees is to provide a safe and healthy working environment and to ensure business continuity.  All of us received an email outlining our policies along with a link to an internal portal page dedicated to Emergency Preparedness.  It contains several governmental and informational resources pertaining to H1N1 along with Emergency Hotline Phone Numbers and a short video from HR so we all can clearly understand this particular flu strain and what to do if we contract it.  Each region around the world has a page specific to their needs.  We have also put together a cross functional pandemic planning team that has identified critical business activities, resources and responsibilities to support a pandemic mission along with taking precautions within our own facilities – like simply providing hand sanitizers among other supplies. 
Following tips offered by the Centers for Disease Control, if any of us do get symptoms, one of the primary actions we can take as employees is stay home since the virus appears to be easily transmitted from person to person.  This is to protect all employees.  The great thing is that there are also Work from Home instructions on how to connect remotely using our own FirePass SSL VPN.  We’re already prepared for any increase in needed capacity and have policies in place to check any connecting device, even un-trusted home computers, to ensure internal security compliance.
It’s a comfort to me knowing that my employer is ready for H1N1 and any other emergency that suddenly appears and hopefully a comfort to you knowing that F5 is prepared to still support you even if you experience a crisis.
ps

Additional note added after posting:
One thing I forgot to mention about Work at Home strategies - Do keep in mind that with the additional workforce potentially using home broadband for work, there might be some capacity constraints on carriers in certain areas of the country.  There might also be some Acceleration solutions, like a WAN Optimization or Web Acceleration that can help with bandwidth reduction.