Vincent Gullotto, the senior director for McAfee’s Anti-Virus Emergency Response Team (AVERT) has had a hand in detecting and destroying more than 57,000 computer viruses.
That is his job and his bias, of course. But Gullotto believes that virus detection should also be a top job for IT managers, who face a growing virus threat.
His international team is responsible for identifying new viruses and developing the fix. They create the detection DAT file and engine component that work together to detect and remove viruses. But detecting and fixing viruses are only two elements of virus protection.
Gullotto, the keynote speaker at the recent E-Security Conference and Exhibition held in New York, said in a telephone interview that IT managers “…can’t afford to do anything less than what we do” and should adopt a set of proactive virus protection policies and procedures.
That’s a hefty statement, considering it’s Gullotto’s business to provide virus protection. Gullotto offered these nine steps you can take to develop an effective antivirus program, no matter what software you adopt. According to Gullotto, IT managers should:
|More than a third of the respondents to this TechRepublic poll said they were hit by at least two viruses during 2000.|
- Ensure all antivirus software at all points of entry is updated regularly.
- Establish security policies. The policy might include:
- A requirement that all desktops have antivirus detection
- A provision for scanning all files on command or access
- A provision against downloading files from the Internet
- A requirement that all virus detection runs in the heuristic mode, which will look for patterns as well as viruses and can mean earlier detection
- Assign each staff member a virus or form of attack to research and monitor. For instance, some of Gullotto’s staff focuses on Linux, while others are charged with monitoring denial of service (DOS) attacks. Gullotto recommended the Usenet group alt.comp.virus as a good resource for keeping up with trends.
- Require that at least one member of your staff attend a security conference.
- Encourage IT workers to participate in local user groups.
- Make sure you’re familiar with what sort of support and help your antivirus vendor offers. Most offer some advice and support for top-tier customers.
- Create an outbreak checklist that delineates how your staff will recover after an outbreak, he said. After the Melissa virus hit, McAfee defined the steps to be taken internally during an outbreak. The checklist outlines each step needed to mobilize your staff during an outbreak and how to update servers within 90 minutes.
- Find new ways to justify the expense of security. Gullotto said IT managers have done a good job of increasing security over the past couple of years. However, obtaining funds for security is still a challenge. One way to show agency executives the value of security is to explain the cost of network downtime. You should also determine where viruses enter your network and identify products or procedures that will address the problem.
How do you justify security costs?
Gullotto offers good advice for justifying security expenditures, but it remains a challenge for many IT managers. In "Eight tips for justifying security infrastructure investments," we outlined SAN’s recommendations for convincing executives to invest in security infrastructure. Now we’d like to hear your suggestions for securing security funds. We’d also like to hear what challenges you’ve faced when trying to finance security. Post your suggestions or challenges or e-mail us.