Home > Security News > Data theft detective work begins at the office
Security News:
EMAIL THIS

Data theft detective work begins at the office

By Michael S. Mimoso, Senior News Editor
06 Jun 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Intellectual property and other sensitive consumer data are seeping out the doors of corporations at an alarming rate -- and the culprits aren't necessarily a cracker with a broadband connection holed up in his mom's basement, or a wiseguy who's Dumpster diving.

Users nestled inside the enterprise firewall with an abundance of unmanaged privileges are most often to blame, according to a soon-to-be-released study conducted by the director of an identity theft program at Michigan State University.

Theories that the insider threat is greater than that of malicious code and crackers have been floated for more than a year, but the Michigan State numbers quantify them in a frightening manner for IT administrators. More than 1,000 identity theft cases were combed and 70% were traced to the theft of sensitive data from inside a company.

"It's hard enough to prevent a valid user on a valid system from doing something bad," said Jeff Schultz, vice president of sales and marketing for Abridean Co. of Westchester, Ill., a vendor of user management and provisioning software. "But it's too easy for someone who does not belong to get access to a system. There's no way to control it, no way to track it or no way to tell if it's actually happening."

A representative of the Michigan State program told MSNBC this week that many identity thefts happened at health care or financial services companies by employees stealing data from other departments. This falls into line with the thinking that users have more access to data and systems than they need to do their jobs.

"People are granted permission to access many applications and IT loses track of it and often there are no audit records," Schultz said.

Schultz added that disgruntled workers who have been fired or laid off by a company often retain access to at least their e-mail accounts for months after their employment has terminated. Former employees are denied network access, but other avenues into the company like Web-based e-mail accounts or mobile devices like PDAs or cell phones are frequently left within reach.

"That opens you up to a number of things beyond identity theft," Schultz said. "The risk then is enormous."

Role-based automated provisioning systems manage system access and provide the audit trails that many companies lack right now.

"IT departments are stretched thin, budgets are tight and staffs have been cut. There's a lot of pressure on IT to focus on fewer new system deployments," Schultz said. "What happens with internal application security is that months may go by without a major incident and you start to say that there's no need to put something in place; it's the squeaky wheel syndrome."

Regulations like Sarbanes-Oxley and HIPAA are also putting pressure on enterprises to implement and enforce security policies that deal heavily with access to sensitive data. C-level executives of public companies are now forced by law to pay attention to the integrity of their data and have adequate auditing capabilities.

"Until a compliance issue or an identity theft arises, often there's no pressure to proactively do something," Schultz said.



Tags: Security Awareness Training and Internal ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Awareness Training and Internal Threats
Twitter risks, Facebook threats trouble security pros
Social engineering training could disrupt botnet growth
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
Tabletop exercises sharpen security and business continuity
Security policies need simplifying, expert says
Microsoft IE 8 security only benefits educated users
Security book chapter: The Truth About Identity Theft
How to integrate the security of both physical and virtual machines
Laid off workers likely to steal company data, survey warns

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
Honeynet Project  (SearchSecurity.com)
insider threat  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
social engineering  (SearchSecurity.com)
Total Information Awareness  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts