Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Customers mismanaging access

While companies spend millions on stifling data leakage, they are largely doing a subpar job at watching the levels of access various employees have


"This entitlement drag issue is a major problem. IT organizations are under pressure and often either valued or devalued by business based on how quickly they deliver access," said Brian Cleary, vice president of Marketing for Aveksa. "Clearly, the findings here show that that while companies are doing a good job of providing initial or changed access, there is no automated way to go back and make a determination to understand if a workers' current level of access is appropriate."

Lessons learned from Jerome Kerviel
Issues of access control are of fundamental importance to corporate risk management, perhaps best exemplified by the recent reports of the activities of Jerome Kerviel, a stock trader at French firm Société Générale who is accused of losing nearly $8 billion of his company's capital in unapproved transactions carried out by circumventing rules built into the brokerage's IT systems.

Had Société Générale been actively monitoring the access controls for its transactional systems, Kerviel likely would have been caught long before he gambled away such a stunning amount of money, the experts contend.

A major factor contributing to the continued loopholes in access management is a lack of support for improving policies and applying technologies used to govern the issue by senior management in many companies, according to the report. Some 74 percent of respondents indicated that senior management in their companies does not view access governance as a strategic security imperative. "It seems that the perception is that it's still tough to get senior executives to sign off on the necessary funding, but situations like Société Générale may help prove how big of concern this really needs to be," said Ponemon.

Another major contributor to the problem is the need for cross-organization collaboration, which complicates issues of access dramatically.

And while 83 percent of those people responding to the survey said that collaboration among business units, audit and compliance groups, and IT security departments is vital to keeping their operations in line with government regulations, 57 percent said those teams never partner to oversee access issues.

"This has to be an area of great concern, because if companies consistently score poorly on compliance audits it's been proven that this actually starts to diminish their reputation and brands," Ponemon said. "And as more organizations suffer losses, there will likely be new regulations put in place that make it even harder to operate; most businesses I know don't want more regulations, but if more people fail to create their own controls, more regulators will get involved."

Matt Hines is a senior writer at InfoWorld.
« PREVIOUS PAGE | 1 | 2 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Remote Access: Maintain Security and Decrease the Burden on IT
Join this interactive webcast to discover how IT Managers can control access rights, end-user security settings and end-point authorization. Sponsor: Citrix(R) GoToMyPC(R) Corporate

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist