Access and Feeds

Security: Sensitive Data Threatened by Privileged Users?

By Dick Weisinger

You’d think that CEO, top executives or the board at most companies would be the people with access to the company’s most sensitive data.  While 30 percent of companies say that their executives exclusively hold the keys to company sensitive data, more than double that number — 65 percent — say that it’s actually IT members who have the easiest access to sensitive data.  That’s the result of a study made by the security company, Venafi.

A parallel study conducted by the Ponemon Institute and sponsored by HP investigated security threats resulting from abuses made by privileged users, users like  database administrators, network engineers and IT security members.  The report found that 52 percent of privileged users admitted that they had been given access to otherwise restricted or confidential information beyond the requirements of their position.  60 percent of these privileged users also report that they’ve accessed confidential information, not because their job duties required it, but just out of curiosity.

Dr. Larry Ponemon, chairman and founder, Ponemon Institute said that “it not only is a tech related problem, it’s also about culture.  Somehow privileged users think they have a right to access.”

The HP report found that data most at risk was customer information. and general business data.  Ponemon said that “the findings demonstrate key areas of concern, and clearly identify budget, identity and access management technologies, and network intelligence technologies as the three most critical success factors for governing, managing and controlling privileged user access across the enterprise.”

One solution for better security data is encryption.  But that can lead to its own set of problems too.  Jeff Hudson, CEO of Venafi, said that “companies are finding out how important encryption is when they have experienced a huge data breach because they weren’t using encryption, but then they find out that when they deploy encryption that they have another big problem, and that is managing the encryption keys.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*