
THREAT MONITOR
Does blogging pose enterprise information security risks?
Mike Chapple 09.15.2006
Rating: -4.00- (out of 5)




|
Blogging is growing in popularity and rapidly becoming a mainstream communication tool. Even companies are jumping on the bandwagon in record numbers, as a recent American Management Association/ePolicy Institute study of 416 U.S. businesses found 8% of organizations operate official corporate blogs. That's no surprise, given some of the high-profile business blogs, such as those by Justin Rattner of Intel and John Dragoon of Novell. However, the same survey also revealed some troublesome statistics regarding corporate blogging policies or lack thereof. Specifically:
Those are somewhat shocking numbers. While blogging is a powerful marketing and communications tool, it can pose significant risks to enterprise information security when not controlled. While some of these risks are obvious, such as inadvertent (or intentional) disclosure of trade secrets and risk to a company's reputation, other risks are more nuanced. Therefore, if your company is publicly traded, blog postings should be considered in light of applicable Securities and Exchange Commission regulations, because a blog post is like any ot
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com

her corporate communication.
Blogging policies
What can you do to control these risks? As with many security issues, the best place to start is with policy. Here are some questions you should consider when drafting your information security policies:
Blog risks go beyond policy-related concerns as well. A recent SPI Dynamics study noted that content feeds may be used as an attack vector to exploit vulnerabilities in news reader clients. Expect to see this threat develop over the next year, and be certain to keep your blog-reading software up-to-date on vendor security patches to reduce the risk to your enterprise.
About the Author:
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles, including the CISSP Prep Guide and Information Security Illuminated.
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |