Dan Farber reports on IBM's $1.5 billion security push, dubbed "an enterprise free of fear." (Note to IBM: "Free from fear" would be the more direct way of saying it.) But IBM, like others, is approaching security as code an enterprise would layer on other code, and processes on top of that code, rather than something inherent in the code itself, as Stuart McIrvine, director of IBM?s Corporate Security Strategy, relates:
"Our approach is that security is kind of broken. Companies are leaving security in the hands of IT and operations people, looking at servers, databases and putting up firewalls and updating antivirus signatures. But they have no real view of what they are protecting from a business strategy viewpoint, understanding the core objectives and risks to meeting those objectives."
...