All the latest UK technology news, reviews and analysis

HP study finds security holes in privilege management

by Shaun Nichols

12 Dec 2011

Be the first to comment

  • Tweet this
A security pass reading 'Access All Areas'

Many companies are still failing to adequately manage user privileges and protect sensitive data, according to a study from HP and the Ponemon Institute.

The survey which polled IT administrators from 13 countries including the UK, US, Germany and France, found that more than half allow access privileges beyond what is needed for their users' current roles with the company.

Among those employees who are given access to sensitive information, abuse of privilege is rampant. Some 63 per cent of those surveyed reported that curiosity has driven privileged users to access sensitive or confidential data.

Additionally, the study found that few companies have systems in place to adequately manage and view how user privileges are assigned and how they are used.

"It not only is a tech related problem, it's also about culture," said Ponemon Institute founder and chairman Larry Ponemon.

"Somehow privileged users think they have a right to access."

To change that culture, the HP and Ponemon believe that firms need to adjust their approach to the way user rights and privileges are managed.

Ryan Kalember, senior director of solutions marketing for HP enterprise security products, told V3 that rather than looking to assign strict privileges on user access, companies should make more of an effort to monitor and analyse access patterns.

When administrators are able to view how data is accessed, IT departments can gain a clear picture of what rights are required for each role and flag unusual or specific behaviour, he said.

Much of that change, said Kalember, will rely on shifting the conventional approach to access management and repurposing existing monitoring and analysis tools for access and activity logs.

"There is a measure of correlation that you have to do in order to get this right," he explained.

"That information is not necessarily married up with identity information, so that is a technical process to solve."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

39%

0%

10%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.