But there is no evidence that either party has actually analyzed the cost of diversity or quantified the risks of diversity. It appears clear they came up with the solution and then fit the facts of the problem into an argument that supports that conclusion.
We have yet to see a cost/benefit analysis that supports the conclusion that a heterogeneous computing environment lowers the overall threat level of a corporation, or that it is the most cost effective of the choices available to you.
While diversity may -- and I stress may -- lower the extreme threat of some types of attack, diversity would have failed to protect enterprises from most of the attacks that have occurred to date. Few companies can continue to function if even 30% of their systems fail catastrophically. However, diversity will clearly increase costs sharply for sites that are highly consistent now. And diversity may even be less secure than a monoculture, increasing exposure to other types of attack.
A much better approach is to look at the entire security problem first, including the risks and costs of not doing anything, so that you have a foundation on which you can build alternatives. These alternatives include:
- Diversity.
- Accelerated adoption of patches.
- Locking down desktops so users cannot make changes and viruses and worms can't install themselves and run.
- Restricting ports, such as port
- Implementing additional security products, such as virus software and firewalls.
- maintaining "hot sites," or duplicates of key elements of the IT infrastructure, so if the main infrastructure is compromised, users can quickly switch to backup systems.
- Developing the capability to rapidly restore compromised software and data from backups.
- Deploying Windows on alternative hardware. For example, "PC blades" centralize the processors, memory and storage of PCs in a datacenter, while the display, keyboard and mouse are at the user's desktop. PC blades give users the benefit of having their own dedicated PC, while keeping the hardware in a centralized location where it can be more easily maintained and secured.
- Adding security staff or outsourced services.
The result of this analysis would be a security plan that is optimized for your environment. Even if you chose diversity, you could show that you went through a solid decision process before you reached the decision you made, and it wouldn't look like you were ticked at Microsoft and simply shot from the hip.
I'm not a big fan of diversity because so much the research I've done over the last decade or so indicates that by eliminating diversity you can dramatically reduce costs. Companies can minimize support costs by rolling out identical hardware and software to every desktop through big bang deployments. Going the other way in a knee jerk reaction to just one class of security threat seems poorly founded.
More Software Insights
White Papers
Webcasts
Reports
80 135, which effectively stopped the latest virus attack. (Corrected Friday 10/10/03.)
Videology Imaging seeking Software Architect in Greenville, RI
Beyond.com seeking Database Developers in King of Prussia, PA
Mentor Graphics seeking Sr. Director of Sales in San Jose, CA
Mesalands Community College seeking Comp Sci Instructor in Tucumcari, NM
Sectoral Asset Management seeking IT Manager in Montreal, QC
For more great jobs, career-related news, features and services, please visit our Career Center.
Green IT: The Next Priority for Enterprise Data Centers
Green IT is a label for a movement in the IT industry to solve these problems through hardware and software advancements, efficient data center design and best practices. This eBook covers the primary issues facing Green IT today and tomorrow.
read more 
NOTE: Offer valid for U.S., U.S. possessions, & Canada only