When is there too much security?
Adding layer after layer of security sometimes actually gets in the way of securing your computer.
I was recently surprised when someone asked me what anti-virus programs they should be running. Note, he said 'programs,' not program, and that's what he meant. He thought that if one A/V (anti-viral) program would do him good then two or three would be even better.
Ah.... no, that's not how it works.
While it's certainly true that one A/V program will catching something that another program might miss, if you add layers of A/V software to one PC, you're asking for the two of them to clash with each other. The end result is a PC that will certainly run slower, and might very well stop working from time to time because of conflicts between them.
You're much better off if you just get one good A/V program and keep it updated.
The same is also true with firewall and other security programs. Multiple layers of the same kind of protection on a single PC just means that there are more ways for things to go wrong, not better, added protection.
It's a different story if you're running a network. Even on a small network you should have firewalls both on your PCs and on your server or device that stands between you and the Internet, like a SONICWall TZ or NSA Series appliance. You'll still need to make sure that everything works smoothly together. I can't count the number of times I've found that an Internet program was 'broken' because while one firewall let the software access its required port, another blocked it.
Finding and fixing that kind of problem comes with a network administrator's job. With so much malware and automated network attacks on the Internet, you have no choice but to block potentially dangerous connections from both your network as a whole and on each individual PC.
I also run a different A/V program on my servers, especially my mail server, than I do on my PCs. Since I'm not running the programs on the same box, I avoid the problems of conflicting programs, while making sure that I don't miss any problems on the servers.
Here again though I'm not going to run multiple programs to do the same job on the same box. If you try that, workstation or server, you're just asking for trouble. And, after all, the entire point of using security software in the first place is to avoid trouble.
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
Esther Schindler
If the comments are ugly, the code is ugly
claird
SVG a graphics format for 21st century
pasmith
Take Chrome OS for a test spin
Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?
jfruh
Android fragments vs. the iPhone monolith
mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.














When?
Too much security is when there's no single place to go and get a picture of where everything stands that doesn't require a geek to get it. A proper and effective security posture is one where a CEO can pull up a screen and decide for themselves if everything is AOK. Security is a process not a product.Heard of HIPS?
Avira Antivir + ThreatFire + Firefox NoScript + Sandbox + VM = Not too muchEach has caught many baddies.
Also
-Take disk image backup of the OS regularly
-Run browser and email sandboxed or in a virtual machine
-Keep your most valuable data off the net
TF is one the least customizable HIPS out there, but recommendable just because of this: install it and it just works.
Couldn't aggree more.
Right now I am helping somebody that had Shaw put Shaw Secure on their Laptop. After the install failed they tried to get it uninstalled. This didn't work and now they could not access the internet though IE. When I look at it I found they had 2 firewalls + plus what Shaw Secure left behind and 3 AntiVirus. I am having a very tough time reverting the changes as even a system restore won't work and have verified that the hardware is good by Ubuntu Live CD. I have only got the mail programs and the Windows updates working.