Friday | 10 July, 2009
CSO
Half of 2006 vulnerabilities still unpatched
Apple security holes set to outnumber Microsoft
Darren Pauli (Computerworld) 12/02/2008 16:59:19

Alloy said security vulnerabilities will increase as social networking is incorporated into business processes. Hackers can create targeted phising attacks or gain direct access to the network by using corporate and personal information inadvertently posted online by staff.

"If they take everything, I've still got a mattress and a Smith and Wesson," Alloy said of the ability of hackers to steal identities.

IBM global technology systems senior managing consultant Andrew Gontarczyk said enterprise should primarily focus security efforts on policy enforcement and good business culture.

"Risk management and compliance are the biggest drivers for security. Businesses must consider who they employ and why, and build security around it," Gontarczyk said.

"Its a balance of tightening access rights and doing things like appropriate background checks, while still allowing the business to function smoothly.

"You can tick all the boxes in the compliance checklists and still be open and exposed, because the checklists always [lag] behind the threats - the point is holistic security."

Gontarczyk said weak corporate policies are the biggest cause of data leakage from accidental data losses and employees tempted to steal information.

He said encryption and solid access management should be the second security priority for business because it can prevent disgruntled employees from stealing data, minimize the effect of information lost on removable drives, and help locate the cause of the security breach.

Allor said enterprises are typically 80 percent secure because the remainder is difficult and expensive to protect and requires constant modification due to changing business requirements.

Click to send your opinion to Darren Pauli.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Peter Allor, intelligence director at IBM ISS
Peter Allor, intelligence director at IBM ISS
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

The business justification for data security

In the information security world we face two major types of threats: "noisy" threats which directly interfere with our ability to do business and "quiet" threats which cause real damage, but don't necessarily prevent people from doing their jobs. Read on to discover how to combat both types of threats and to justify the use of data security within your business.

Sponsored Links