Google gives glimpse into security strategy

By Tim Ferguson, Special to ZDNet Asia
Monday, April 14, 2008 09:03 AM

Google has outlined some of the methods it employs to keep its IT security tight.

Google director of product management Scott Petry--founder of Postini, which is now owned by the search giant--gave the low-down on the Web giant's approach to security at the RSA Conference in San Francisco this week.

Petry said: "Google is possibly the number-one target on the Internet today. We get an enormous amount of activity against our systems."

He added: "We can't do everything and we know that. No security measure is 100 percent perfect."

Petry pointed out that the increasing number of different devices and mediums available--such as YouTube and the iPhone--is having a huge impact.

He said: "The base tenets of security aren't changing, but the world around us is. The data is finding different ways to get out into the world."

One way in which Google tries to reduce its exposure to risk is by using an army of external testers to "hammer" code, with the aim of revealing and reporting any vulnerabilities on new releases.

Petry explained: "If you don't know what your risk is, you don't know how to manage it."

Google also uses a neighborhood-watch approach, asking people to confidentially report vulnerabilities they discover. Close competitors have taken part in this program and Google returns the favor.

Security training is also very much part of the Google culture, Petry said. "Educating people about security is about the most important thing a security professional can do."

New recruits--known as "nooglers"--are thoroughly trained in the company's security policies, while a peer-review process means new code is checked a number of times before going live.

Petry also said that Google establishes "guard rails" for employees--for example, the use of technology that measures the strength of internal passwords when users first create them.

Tim Ferguson of Silicon.com reported from London.


See also:  Security
WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Secure ASP.NET sites with Membership API

Web Development

Beginning with ASP.NET 2.0, the Membership API was added to simplify adding security to a Web application. Find out how to use the Membership API with a SQL Server backend.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attacks
  3. botnet
  4. credit
  5. data
  6. details
  7. dns
  8. facebook
  9. fix
  10. flaw
  11. flaws
  12. fraud
  13. google
  14. iphone
  15. issues
  16. microsoft
  17. olympics
  18. oyster
  19. patch
  20. researcher
  21. researchers
  22. security
  23. spam
  24. storm
  25. team
  26. uk
  27. us
  28. users
  29. warns
  30. worm

ZDNet Asia Top Tech 50 to recognize Asia's potential

Blog thumbnail

The ZDNet Asia Top Tech 50 awards are back, and we're once again seeking nominations to identify the industry's best-performing tech companies.

The marketplace is crowded with players clamoring for..... by Eileen Yu

Read more »