Showing posts with label insider threat. Show all posts
Showing posts with label insider threat. Show all posts

Wednesday, December 17, 2008

The security double whammy

A lot of the recent news is about how the recession will cause increases in cyber threats. Combining that with reduced investment in security, and you have a true double whammy. And some want to add icing to the cake by suggesting that employees will also become more tempted to steal data..

Nice - a triple whammy!

Organizations should be cognizant of the tradeoffs they are making from a risk management perspective. Even if one cannot get everything complete, use the old 80/20 rule to ensure the high priority and projects that will reduce the most risk get implemented. No use being penny wise and pound foolish...

Monday, June 23, 2008

The "IT admin bad guy"? Not sure I buy it much..

The recent survey on IT Admins misusing privileges might be accurate - but am not sure I buy it much. I'd like to see some of the questions as well :)

Most of the IT admins I have met with have a sense of the responsibility that comes with their power. True, there might be some bad eggs or apples in the bunch, but overall I think they are ethically sound people.

This is like implying that since the guard to the safe has access to it, he/she might be taking advantage of that ability. My view is that the state of technology is (or was) such that there is no way around it - there had to be someone who has access.

However, to get this monkey off the back of IT admins, all they have to do it install technology that creates isolation between content and infrastructure. IT admins don't lose anything - they get their work done, and they wont be scapegoats for leaked data or bear the burden because of a few rotten apples.

I spy - employees snooping around?

Apparently many employees ( nearly half ) have the habit of snooping around within the company. This according to a new research study by Cyber-Ark. Many gain access using privileged accounts such as administrator or root passwords, which the research found were not changed that often.

"Cyber-Ark said privileged passwords get changed far less frequently than user passwords, with 30 percent being changed every quarter and 9 percent never changed at all, meaning that IT staff who have left an organization could still gain access."

This is a bit unnerving - most organizations should be following compliance mandates such as SOX to isolate administrator access from content. And using technology to enforce this..