Sun and Oracle Community Voices How to Buy Log In United States [Change] English

»  Contrarian Minds Archive
Balancing Act

Managing Security in an Open World

Story by Al Riske. Photography by Howard Friedenberg.

23.May.08 - Leslie Lambert's job is managing a paradox. A worldwide paradox. A paradox that involves unfettered access and the opposite of unfettered access.

he job involves vulnerability assessments, intrusion detection, and incident management. It involves virus protection and spam filtering. All on a network that spans more than 100 countries.

And those are just the basics.

What Lambert would call the easy part.

Nothing to lose sleep over.

The paradox is that the network has to be simultaneously open and closed. Open to employees, customers, partners, and suppliers. Closed to spies, thieves, spammers, and con artists.

Call it a balancing act.

"Leslie has a nearly impossible job. We're asking her team to protect our intellectual property, while at the same time not inhibit employee choice, productivity, or mobility."

Bob Worrall
Chief Information Officer
Sun Microsystems

 

Lambert has been with Sun for 16 years and can remember when security was the group that said no to everything.

Not safe, don't do it.

Well, the job has changed.

Many companies still limit the choices available to their employees. You can use laptop A or B, cell phone 1 or 2. That's it. Nothing else.

Not Sun.

Most corporations, she says, actually block access to social networking sites such as Facebook, MySpace, and Ning.

Not Sun.

Lambert's job would be a lot easier. No question. But what would be the fun in that?

"It's really boring to say no. People don't come back. You don't have any friends. But if you partner with them ..."

Leslie Lambert
Chief Information Security Officer
Sun Microsystems

 

Leslie Lambert

Lambert was actually the head of the security group in the old just-say-no days. But it wasn't even a full-time job then. Just one of three things she was doing for Sun. IT strategy and architecture work being the other two.

Now, she is Sun's chief information security officer, and it's full time.

She reports to CIO Bob Worrall, who says, "Leslie has a nearly impossible job. We're asking her team to protect our intellectual property, while at the same time not inhibit employee choice, productivity, or mobility. This means rethinking many of our old security policies and practices."

Her team comprises 21 individuals with a combined total of 272 years of Sun experience.

"I challenge them and say, 'Tell me what's possible. Don't just say, Shut it down. I'm the VP. I could tell you how to shut it down,'" she says.

"I challenge them to be smarter than that.

"It's really boring to say no. People don't come back. You don't have any friends. But if you partner with them ... "

"Then we take it further, with Web 2.0 and all the social networking pieces. We always want to be a leader in that kind of thing. But how do we do it and still keep our company and its information safe?"

Leslie Lambert
Chief Information Security Officer
Sun Microsystems

 

"Sun has always had an extended family with resellers and partners who help us in our mission," Lambert says, "so we invite them to participate in SWAN [ the name for Sun's wide-area network] and use some of our tools."

Which more than doubles the size of the community, to around 80,000 people.

"It makes the job much more complicated and broader than most people expect," she says.

Leslie Lambert

"Then we take it further, with Web 2.0 and all the social networking pieces. We always want to be a leader in that kind of thing. But how do we do it and still keep our company and its information safe?"

Sun has more than 4,000 bloggers, more than 6,000 Facebook friends, and no less than seven islands in Second Life, where it has staged numerous public and private events, including a virtual town-hall meeting in which Sun's top executives recently came avatar-to-avatar with employees around the world.

"We enable Sun to do that by managing security behind the curtain," Lambert says. "The tagline I have for my team is: We enable Sun to be Sun."

"What we've done, in the case of Second Life, is we've partnered up with folks. We said, 'Hi, we're from security. We're here to help.' Once people recovered from the shock, we said, 'We'd like to enable you to do this, and we're going to show you how to do it safely.'"

"The problem with a lot of these sites is they don't necessarily apply the same degree of security rigor to the information stored there that we do at Sun."

Leslie Lambert
Chief Information Security Officer
Sun Microsystems

 

Initially, Second Life was not available on SWAN.

"So what we did, with my technical people behind the curtain, was work on exactly how we could configure SWAN and the ports in the firewall to allow Second Life to come in and out in a secure manner," she explains.

Other social networking venues are harder to secure -- "Honestly there's not a whole lot we can do, physically" -- so Lambert and her team are relying on awareness.

"We're addressing it more through policy and guidance and training for people right now," she says.

"The problem with a lot of these sites is they don't necessarily apply the same degree of security rigor to the information stored there that we do at Sun," she says, "and I don't know that everyone across Sun necessarily understands that."

In other words, employees have become accustomed to the seamless security of Sun's network.

"We've lulled people into a false sense of SWAN. They think SWAN is reality when it's not reality. It's far from reality," she says. "We've architected all this stuff to allow people a very free environment, yet it's very safe. They may presume that's what it's like on the outside -- and it's not."

"They don't realize that all of that stuff is fully exposed for all the world to see."

Leslie Lambert
Chief Information Security Officer
Sun Microsystems

 

"The biggest issue is that people might inadvertently post the company's confidential information on these sites thinking they're safe to use and this is how I'm getting my group to collaborate or this is how we're arranging meetings with an outside agency," Lambert says.

"They don't realize that all of that stuff is fully exposed for all the world to see."

Leslie Lambert

She points out, however, that Sun's experience with blogging over the past four years has been overwhelmingly positive, with nothing to prevent people from posting confidential information other than a set of guidelines.

Trust and common sense make it work.

"We'd all prefer to make things more secure, but given who we are, we're not going to make it that arduous on the user. I've been in meetings with Jonathan [Schwartz, Sun's CEO] where he's said, 'I'd prefer to have two-factor identification on everything that people put out there on Facebook, but that's not reality.' In effect he's challenging me and my team and others to be smarter than that. Like I said, it's easy to shut it down. It's difficult to figure out how to do it safely."

Leslie Lambert Portrait
Leslie Lambert

Title: Chief Information Security Officer.

Duties: Responsible for overall IT security management, including intrusion detection, virus protection, spam prevention, vulnerability assessments, incident management, and security awareness.

Quote: "My secret sauce on the whole thing is not telling people no but telling them how."

What Other's Say: "Leslie has a nearly impossible job. We're asking her team to protect our intellectual property, while at the same time not inhibit employee choice, productivity, or mobility." - Sun CIO Bob Worrall.

Education: MBA with an emphasis in finance and marketing from Santa Clara University. Bachelor's and master's degrees in experimental psychology from California State University, Fullerton. Additional degrees in math and engineering technology from Saddleback College and Rio Hondo College. Graduate-level studies in computer science at California State University, Fullerton.

Background: Twenty-seven years of experience in information technology and business/technical infrastructure. Joined Sun in 1991.

Awards: CIO Magazine "Ones to Watch" Award in 2005. Anita Borg Institute Ambassador in 2006.

Commentary: "The Growing Importance of Identity to Information Security," by Leslie Lambert.

Hobbies: Travel, hiking, scuba diving. ("I've been on all seven continents, including Antarctica. That was a personal goal of mine.")

Favorite Destination: Italy.

Little-Known Fact: Had to be rescued by helicopter once on an ill-fated backpacking trip.

Last Book She Read: Exile, by Richard North Patterson.

Pet Peeve: "I hate voice mail. It takes extra time. You have to write down what the person is saying, and some people go on and on and on."

Favorite Movie: The Way We Were.

Theme Song: "Danger Zone," by Kenny Loggins (from the movie Top Gun).

Favorite Beverage: "Coffee. It's an addiction."

First Job: Paper route at age 11.

Childhood Ambition: Save the universe.

What Keeps Her Up at Night: "How to protect Sun's information in this new Internet economy."

Why She Sticks with It: "Sun has always provided for me the absolute perfect environment in which to work. I spent quite a few years at different companies where it was like: 'Penalty! Get back in the box!' I hate that. Sun let's you be much more creative."