Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Security Risks Rise due to Mismanaged User Access: HP

    in Security



    Article Rating:starstarstarstarstar / 3
    Article Views: 3746

    Top barriers to enforcing privileged-user access rights are the inability to keep pace with change requests.

    Rate This Article:
    Add This Article To:

    Increased threats to sensitive and confidential workplace data are being created by a lack of control and oversight of privileged users, including database administrators, network engineers and IT security practitioners, according to a new report, entitled “The Insecurity of Privileged Users.”

    The study, sponsored by Hewlett-Packard and conducted by the Ponemon Institute, revealed that 52 percent of respondents are at least likely to be provided with access to restricted, confidential information beyond the requirements of their position.

    More than 60 percent of the respondents reported that privileged users access sensitive or confidential data out of curiosity, not job function, with customer information and general business data at the highest risk. The most threatened applications included mobile, social media and business unit specific applications. The global survey focused on more than 5,000 IT operations and security managers across Australia, Brazil, Europe, Asia and the United Kingdom and the United States. Many respondents claimed to have well-defined policies for individuals with privileged access rights to specific IT systems.

    However, almost 40 percent were unsure about enterprise-wide visibility into specific rights, or whether those with privileged access rights met compliance policies. Twenty-seven percent said their organizations use technology-based identity and access controls to detect the sharing of system administration access rights or root-level access rights by privileged users, and 24 percent said they combine technology with process. However, 15 percent admitted access is not really controlled and 11 percent said they are unable to detect sharing of access rights.

    “This study spotlights risks that organizations don’t view with the same tenacity as critical patches, perimeter defense and other security issues, yet it represents a major access point to sensitive information,” said Tom Reilly, HP’s vice president and general manager of enterprise security products. “The results clearly emphasize the need for better access policy management, as well as advanced security intelligence solutions, such as identity and privileged-user context, to improve core security monitoring.”

    Top barriers to enforcing privileged-user access rights are the inability to keep pace with change requests, inconsistent approval processes, high costs of monitoring and difficulty in validating access changes, the report found, while areas for improvement included monitoring privileged users’ access when entering root-level administrative activity, identifying policy violations and enforcing policies across an entire organization.

    The potential for privileged access abuse varies from country to country based on responses, with France, Hong Kong and Italy having the greatest potential, and Germany, Japan and Singapore having the least. Nearly 80 percent of respondents reported that deploying a security information and event management (SIEM) solution was critical to governing, managing and controlling privileged-user access rights.

    “The intent of the study is to provide a better understanding of the state of access governance in global organizations and the likelihood privileged users will abuse or misuse IT resources,” said Larry Ponemon, the Ponemon Institute’s chairman and founder. “The findings demonstrate key areas of concern, and clearly identify budget, identity and access-management technologies, and network-intelligence technologies as the three most critical success factors for governing, managing and controlling privileged-user access across the enterprise."

     





    comments dic


     
     
    >>> More Security Articles          >>> More By Nathan Eddy
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement