Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > Does password sharing in international branches violate SOX?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Does password sharing in international branches violate SOX?

David Griffeth, past SearchSecurity.com expert EXPERT RESPONSE FROM: David Griffeth, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 December 2008
I worked for an NYSE-listed company. Our IT contractors in India were using each other's passwords, which I believe is a clear violation of SOX. I gave substantial proof to my IT manager. He did not take any actions against the contractors in India. What should I do? Is it indeed a SOX violation, and what are the implications?

>

The Sarbanes Oxley Act of 2002 does not explicitly address password management. Section 404, perhaps the law's most notorious clause which deals with the internal controls required for financial reporting, states that it is "the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting; and contain an assessment, as of the end of the most recent fiscal year of the issuer, of the effectiveness of the internal control structure and procedures of the issuer for financial reporting." If password sharing and the process and controls around it are documented, and the risk associated with this practice is accepted formally by the business, there is no need to interject yourself into the situation.

If this is not the case, the manager may not understand the risks associated with password sharing. I recommend drafting a document to share with management that identifies the threats associated with password sharing and the consequences of those threats being realized in real-world terms.

The document should not only include the possible business effect and real-world repercussions, but also the appropriate process for account management that should be in place, namely one account for each individual. As an information security professional, urge the manager to contribute to the document and reach out to the business line to consult with them on putting proper account management or formally documenting their acceptance of this risk.

In general though, the practice of password sharing is inappropriate and represents risk to the organization because there is no accountability. One way to curtail it is to collect some user authentication data, such as city of birth and mother's maiden name, for all contractors. When the contractor calls in to reset his or her password, the help desk can ask for this information and compare the answers. This gives more assurance that the person calling is the owner of the ID.

More information:


BROWSE BY TAG
Identity Management and Access Control,   Security Audit, Compliance and Standards,   Sarbanes-Oxley Act,   Password Management and Policy,   Enterprise Identity and Access Management,   Identity Management Technology and Strategy,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Identity Management and Access Control
Is Identity Management as a Service (IDaaS) a good idea?
How to log in to multiple servers with federated single sign-on (SSO)
How to confirm the receipt of an email with security protocols
Learn about enterprise strategy for server virtualization single sign-on
Employee information security awareness training for new IAM systems
Can you combine RFID tag technology with GPS to track stolen goods?
Is there a free enterprise-caliber password-management tool?
Cryptosystem attacks that do not involve obtaining the decryption key
Can any firm or organization get a digital signature certificate?
Should the CTO have domain administrator access?

Sarbanes-Oxley Act
SOX compliance burdens midmarket security teams
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Consensus Controls project aims to set benchmarks for compliance
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
RSA attendees see data classification, rights management projects stumble
Sarbanes-Oxley Act Research

Password Management and Policy
Two-factor authentication, vigilance foil password theft
Group to shed light on secure identity management threats
Brute force attacks target Yahoo email accounts
Best Identity and Access Management Products
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
How to prevent brute force webmail attacks
Best practices for a privileged access policy to secure user accounts
Mature SIMs do more than log aggregation and correlation
PCI compliance requirement 2: Defaults

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
graphical password  (SearchSecurity.com)
identity chaos  (SearchSecurity.com)
logon  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
OpenID  (WhatIs.com)
salt  (SearchSecurity.com)
session replay  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
TACACS  (SearchSecurity.com)
war dialer  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts