Real words or buzzwords?: Software-Defined

Oct. 23, 2018
Will software-defined technologies significantly change security system capabilities? It is already happening

Editor’s note: This is the 33rd article in the “Real Words or Buzzwords?” series from SecurityInfoWatch contributor Ray Bernard about how real words can become empty words and stifle technology progress.

During my recent in-depth look at Hyper-Converged Infrastructure, I realized that I had also underestimated the significance of “software-defined” technologies. Once again, I need to say that many IT folks – especially enterprise system architects and those involved in data center and cloud engineering – already know most of what I’m about to say, except for my comments about the physical security industry. I’m quoting from several of them for this article.


I first encountered the term “software-defined” in the phrase “software-defined networking” (SDN). Recently, when I typed software-defined into the Google address box, Google auto-completed it as software-defined-networking. I remembered being led to good SDN material via the SDNCentral Twitter feed, and lo and behold I discovered today that its new name is SDxCentral – standing for Software Defined Everything, which is now a company and website name having the @sdxcentral account on Twitter.

SDNCentral was originally founded in 2011, out of frustration about the lack of reliable and easily accessible information on SDN – a purpose close to the heart of this “Real Words or Buzzwords?” series. Because digital transformation continues to drive technology decisions up the corporate ladder, technologists and executives increasingly have to work together to make business-critical (and expensive) decisions. The vision of SDxCentral is to provide these two drastically different audiences with a unifying language and the resources needed to work together to achieve digital transformation.

Software-Defined Definition

In 2014 reported, “Software defined is a term used to describe a wide variety of products, but it’s often used to catch your attention rather than describe a product’s function.” That is one of the reasons for this article, as the fuzzy use of the term still continues.

Brian Kirsch, an IT instructor who specializes in virtualization and cloud architecture at Milwaukee Area Technical College, said in the above-linked article, “Software defined is one of the biggest buzzwords since ‘cloud’, and yet ‘software-defined’ has existed for many years.” Kirsch also said, “This does not mean that we should stop using the term software-defined. Rather, we need to understand that this term has been around for a lot longer than we realize and that it is getting to be more important.”

Kirsch further explained (I added the bold emphasis), “When a collection of products becomes a commodity and software abstracts and defines its form and function, that is when you have a product that is truly software defined. Until then, it might simply be a collection of products with new software features.”

In the same article, Keith Townsend, an IT management consultant who is currently a Solutions Architect at VMware, further explains, “Software-defined is the ability to abstract the management and administrative capabilities of the technology. For example, with SDN, it’s the ability to control the provisioning of network devices, VLANs, firewall rules, etc.” This abstraction of the control functionality means that it doesn’t matter what the underlying technology is. The software takes care of the details that relate to the underlying technology, allowing humans and automation to specify how the underlying technology must perform.

The Abstraction of Control

Abstracting device control out of the hardware and into its own software control plane allows the management of the technology resource pools to be defined via rules and policies, allowing additional hardware resources to be added to the infrastructure and be automatically provisioned. Just think for a moment what this means for the scalability of networks and systems. The staff requirement for infrastructure management can grow incrementally, while the infrastructure scales up dramatically, thanks to policy-based automation control.

Software-defined networking was pioneered by Google and Facebook to abstract network architecture and make network devices programmable. Its goal is to make networks more dynamic, easily manageable, and easily scalable. Given the vast amounts of data that must flow in real time at Google and Facebook, and the extent of their data networks, it’s easy to see how they would benefit from such technology.

Software-Defined Everything

Rob McShinsky, a senior system engineer at Dartmouth Hitchcock Medical Center, said, “Here is my take on what software defined means:

  1. Abstraction of physical resources
  2. Automation of actions
  3. Predictive configuration or control of workloads, stretching the grip past administrator-defined rule sets for resources.”

So now we also have the following technologies, which are accurately defined by Rob in the article: Software-defined storage, software-defined compute power, and software defined data centers – with more software-defined technologies recently arriving.

It is important to understand where information technology is moving, because it’s moving in directions (such as software-defined technology) that take security technologies and their deployments to capabilities never possible before. Speed of data flow as-needed across integrated systems made possible by just-in-time responses by automated resource pool configuration as well as predictive shifting of resources based upon anticipated needs. This kind of technology infrastructure is required to effectively apply video analytics and other security system functions to unfolding risk scenarios in real time.

This means an end to the over-sizing of electronic security system designs to handle the maximum possible usage scenarios, when those scenarios won’t be occurring most of the time. Cloud-computing technology, with its many software-defined elements, is bringing self-scaling real-time performance capabilities to physical security system technology.

Hyper-converged infrastructure, like the products from Pivot3, and smart video appliances like those from Eagle Eye Networks and its Cloud VMS, are already making high-performance video deployments more affordable than ever before. Security and IoT infrastructure management at large scale is provided by the cloud-based services of Viakoo, which provide proactive, preemptive and predictive service assurance for electronic physical security systems and their IoT devices, including automated firmware management for video camera deployments of any size. You probably know these names, but do you know where their solutions stand today? You are likely to be pleasantly surprised.

The Future of Security Technology Infrastructure

The history of information technology is echoed in the history of physical security technology advancement. In earlier articles I have referenced my diagram titled, Advancing Physical Security Technology, which I have updated now to include Software-Defined Everything. The top of the diagram is Evolvable Intelligent Infrastructure, and having read this article, you can get a better idea of what I’m referring to by that phrase.

This is the future of security technology deployment, and software-defined-everything is a key element for scalability of the growing electronic security system infrastructure of many medium and large size organizations.

About the Author:

Ray Bernard, PSP CHS-III, is the principal consultant for Ray Bernard Consulting Services (RBCS), a firm that provides security consulting services for public and private facilities ( In 2018 IFSEC Global listed Ray as #12 in the world’s top 30 Security Thought Leaders. He is the author of the Elsevier book Security Technology Convergence Insights available on Amazon. Mr. Bernard is a Subject Matter Expert Faculty of the Security Executive Council (SEC) and an active member of the ASIS International member councils for Physical Security and IT Security. Follow Ray on Twitter: @RayBernardRBCS.

(Image courtesy
Both converged and hyper-converged infrastructure provide a pre-configured package of software and hardware in a single system for simplified management. But with converged infrastructure, the compute, storage, and networking components are discrete and can be separated. With hyper-converged infrastructure, the pre-configured package is a single product provided by a single vendor. The way it scales up is by up by connecting more pre-configured packages together, whose infrastructure management software keeps it all looking like a single package to its users.
(Photo courtesy Image)
In the next 20 years we’re going to see some very smart built environments, but they won’t be built using the thinking we used to create 99 percent of the built environments we have on Earth today. That’s why we must put aside, without entirely forgetting, our legacy 20th century security technology thinking and get fully into the 21st century.
(Image courtesy
What does 'future-proof' mean for the security industry in an era of managed services, continuous delivery and ever-accelerating technology advancement? SecurityInfoWatch contributor Ray Bernard explains in the latest entry of his 'Real Words or Buzzwords' column series.
(Image courtesy Denis)
While hype and misunderstanding surround The API Economy, the fact is that it will have a significant impact on the physical security industry moving forward.