Access build-up a new concern for CIOs: security pro

Potential conflict between an organisation's security and its culture

The director of IT security at a national accounting firm has warned CIOs about the increasing level of administration access regular employees are gaining, calling it a “trust time bomb”.

RSM Bird Cameron’s IT security director, Jo Stewart-Rattray, said privilege policy management is a “hot button issue”, as a recent meeting of 16 CIOs highlighted.

“Many thought they were alone in dealing with this problem because it appeared to have an easy fix,” Stewart-Rattray said.

“The challenge is that addressing the user privilege vulnerability creates conflict between an organisation’s security and its culture. User privilege is often associated with trust. However, trust alone is not a control. Without adequate controls, this is a trust time bomb just waiting to explode.”

Stewart-Rattray said the culture of excessive user privileges on computer networks had developed over many years and people are accumulating extraordinary amounts of access that is not needed to do their job.

“One example was an employee who built up a remarkable level of computer network access during years at an organisation,” she said. “When a new employee joined the business, the manager said to copy the network privileges held by the long-serving employee, which is a ridiculous risk.”

Stewart-Rattray is the co-chair of an international taskforce charged with developing strategies to build intentional cultures of security within organisations.

“Cradle-to-grave user management has gone by the wayside,” she said. “CIOs are starting to recognise that there is a dire need for a life cycle management of users, but they are unsure of where to start.”

“One CIO said the challenge is to balance trust with an intentional culture of security. In some respects, because trust has existed historically, we are talking about an intentional change of culture, which is harder. In the beginning, security is intentional and over a period of time, it becomes automatic.”

Stewart-Rattray said privileged user management is a hot topic and a central tenet of this approach is the principle of least privilege.

“Rather than making every user a network administrator, [least privilege] gives each user just the network access required to perform his or her job,” she said. “Even system administrators should maintain a distinction between their privileged account and their day-to-day account.”

Tags: security, IT admin, authentication, access control

Comments

Tepiodide

1

Hey, tell me please, I am now in Mexico, and my parents are in Moscow how to help them so talk to me less? I found just such a an article, maybe someone has used a similar service, or heard of him? Tell me please is it real?

Dimyanshan

2

привет

IMRandall

3

Здравствуйте!
Привет есть колёса, может кто сможет подсказть где лучше всего оставить объявления?

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

ZENworks® Endpoint Security Management

Get Powerful Protection for All of Your Mobile Devices

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.