Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
Computerworld Publication PageNetworkWorld Publication PageCIO Canada Publication PageITJobUniverse.ca
- The Information, Communication and Technology (ICT) Job Board
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network"Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network" read more
From fear to value: CIO strategies for propelling business through the economic crisisFrom fear to value: CIO strategies for propelling business through the economic crisis read more
Reaping the rewards of your service-oriented architecture infrastructureReaping the rewards of your service-oriented architecture infrastructure read more
Yuk it Up
Featured White Papers
Download the Network Barometer Report, which aggregates findings from secure network infrastructure assessments conducted for more than 150 organisations around the world. It provides some surprising stats on the state of network (un)readiness prevalent today; the reasons why organisations are failing at remediating known vulnerabilities; recommendations on assessing your own infrastructure, and on ways to improve your state of readiness to support the business; and more.
Early-generation server load-balancing technology has proven to be an invaluable asset, especially for organizations hosting widely utilized Web applications. But business requirements evolve, as do the processes and technologies used to fulfill them. The many changes and trends that have taken hold since SLBs were first introduced expose the need for enterprises to step up from a simple load-balancing solution to a more comprehensive application delivery solution . This paper is intended to serve as a guide for organizations looking to replace their early-generation SLBs, providing details on the top eight criteria to use during an evaluation process.
Featured Spotlight
Keep up on who's hiring, who's downsizing and how the government is helping. News, job opportunities, recruiters and employment lawyers are all available.
Sign-Up for
Communications Infrastructure
eNewsletter Delivered Weekly
Click here
Page 1 of 2

Digg it Twitter

Symantec: User Ignorance begets internal threats

As monitoring tools become more prevalent, companies are getting a better idea of how much sensitive data is being compromised, and insecure e-mail is a major culprit. Why a toilet paper manufacturer should be concerned about data loss

Most security threats come from inside organizations, but many violators don’t even realize they were doing something wrong, according to speakers at a panel discussion on data loss prevention.

In a recent user survey conducted by IDC, 56 per cent of respondents said e-mail was a source of confidential e-mail links.

Brian Burke, IDC’s program director for security products, presented the survey results during a Webcast Thursday, dubbed Back to School for DLP Education, hosted by Symantec Corp. of Cupertino, Calif.

More than a third of respondents identified Web mail or posts to Web sites as sources of breaches, while 19 per cent cited iPods and other devices that plug into USB ports.

“Three or four years ago companies simply did not know, didn’t have visibility to the fact that employees were committing these errors,” Burke said. “The fact that they’re actually aware of it now and they see it as a major driver signifies a major shift in the level of knowledge out there that this insider threat really exists.”

More in ComputerWorld Canada

Will DLP make your shop more secure?

Web mail was also a concern for Sharp HealthCare, which operates seven hospitals in San Diego. The company’s technical security architect, Starla Rivers, said her organization has a total of 16,000 users, some of whom are doctors working for outside organizations and want to send patient data to Google Docs.

“We’re concerned about patient data going across an HTTP connection, it’s not even an HTTPS connection - and getting posted to Google, out of our control.”

Rivers said another major concern is the prevalence of U.S. social security numbers used on patient records.

“We have widespread use of social security numbers throughout the health care industry,” Rivers said, adding her company also gets confidential information about employees from firms over e-mail.

“The employers are often small, they don’t have the compliance background that we have and they don’t have the tools in place to send data securely, or they don’t use the ones they have,” she said.

Transmitting confidential information over the Web is also an issue for First Advantage Corp., a Poway, Calif. firm whose services include background checks on prospective employees, including including court records, employment history, liens and judgements.

“The biggest challenge we have is our company is we process a lot of personally identifiable information, whether it’s background checks, credit checks or drug testing for large employers,” said Kam Golpariani, First Advantage’s vice-president for security risk management. “We do everything we can to protect our customers data and we have to consider every type of device or system or exit point within our environment to have a good grasp on it overall.”

Although regulatory compliance was cited as important by most respondents to IDC’s survey, protection of intellectual property was also a major driver for DLP technologies,

“We’ve talked to a company that makes wall board,” Burke said. “We talked to a company that makes toilet paper, and these guys are very concerned about their intellectual property – how their product gets put together, design schemes, research plans and things of that nature.” The potential for data leaks through USB ports is real, Burke said.

“I have a 30 GB iPod,” he said. I could download the entire IDC research database and still have room for Desperate Housewives.”

Page 1 of 2
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
CISOReply to this commentReport an innapropriate comment
That's why the detection engine is the most important function of any DLP solution. This engine must have a ZERO False Positive and ZERO False Negative rate. The only solution which has this accuracy is GTB Technologies
Written by: Paul, from NYC
RE: CISOReply to this commentReport an innapropriate comment
We just had a huge data loss incident when one of our VP's sent by mistake an SMS with contacts/confidential information in it. Does anybody know of a Blackberry s/w that would catch this type of message before it goes out?
Written by: James Desato, from Irvine
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

White Papers
Improving business through smart energy and environment policy
Businesses and public entities today face increasing pressure to develop policies that are both good for the planet and good for business. A framework developed by IBM offers businesses and other organizations a comprehensive approach to energy and environmental issues. The framework helps identify and prioritize environmental efforts by breaking down problems and opportunities into seven distinct business areas, which can then be segmented into manageable projects.