Welcome Guest. | Log In | Register | Membership Benefits

SharePoint Users Develop Insecure Habits

Survey finds almost half of SharePoint users disregard the security within SharePoint

Jan 20, 2012 | 04:32 PM | 


The results of a survey, released today, has found that Microsoft' SharePoint users are aware of the risks that exposing sensitive data can cause to their organization, yet unbelievably they are using the collaboration tool as an excuse to turn a blind eye. The study, sponsored by Cryptzone - the IT threat mitigation experts, discovered that while 92% of respondents understood that taking data out of SharePoint made it less secure, 30% were willing to take the risk stating they were “Not bothered if it helps me get the job done”. Thirty four percent confessed they never really thought about the security implications of SharePoint, while incredibly 13% believe protecting company data is not their responsibility. When examining users’ handling of sensitive or confidential information, a defiant 45% of SharePoint users said that they disregard the security within SharePoint and copy sensitive or confidential documents from the collaboration tool to their local hard drive, USB device or even email it to a third party.

The main reasons for copying documents from SharePoint were either to work from home (43%) or share it with third parties who don’t have access to the tool (over 55%). What this practice demonstrates is that this new technology, while supposedly a business enabler, is recognized by many employees as a barrier and doesn’t live up to its full potential as an inclusive collaboration tool to enhance productivity.

Daniel Nilsson, data loss prevention expert at Cryptzone said, “Organizations recognize that today’s workforce needs to be able to collaborate effectively, but if this new found access to data is introducing lax security practices then the danger could quickly outweigh the benefits. While some might consider it admirable that their employees are so dedicated to getting the job done, the fact remains that they’re circumventing procedures and security put in place for good reason. Ignoring the consequences is a risky strategy - is it any wonder then that we see so many data security breaches as a result. Rather than ignoring what’s happening, steps need to be taken that recognize the increasing porosity of the perimeter and allow the workforce to harness the power SharePoint offers without compromising security.”

The study also found that a third of administrators feel users are capable of controlling access rights, but are not given this responsibility. It is unsurprising then that IT Administrators remain overwhelmingly responsible for managing access rights within SharePoint (69%) however this is likely to be higher as 22% of users simply aren’t aware how access rights are managed. Yet, with over a third (35%) of SharePoint administrators snooping around and peeking at documents they’re not meant to read, some organizations clearly aren’t getting the balance right. When digging deeper to see what was being viewed, 34% were looking at employee details, 23% salary details and eight percent merger and acquisition details and even redundancy notices!

Nigel Stanley, Practice Leader for Security at Analyst Firm Bloor Research said, “Whilst hackers and cyber criminals get the headlines, it really is the inside threat that poses the biggest security headache. The survey does highlight the fact that employees for the most part just want to get on and do a good job and will try and get around security measures if these are seen to be a barrier to their work. We need to educate these people as well as put in decent security controls”.

He added, “My biggest issue is with snooping administrators. Trusted individuals that behave in such a way should be kicked out of their jobs and never allowed to work in IT again”.

Daniel Nilsson concludes, “Organizations need to come up with even more innovative methods of communicating cause and effect to their users. Perhaps even consider sanctions to wake up the 12% that don’t consider it their role to protect corporate information. In the meantime, technology exists to provide all the encryption and access rights management tools needed for co-workers to share information securely and assign access rights in line with policies; and strong security features ensure regulatory compliance. Organizations should be confident that information is accessible to those who need it, and protected from those who don’t.”

To download the SharePoint Security Survey Results visit: http://www.cryptzone.com/sharepoint-security-survey



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Database Security Reports

report Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.

report Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.

report Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.

Other reports from the Database Security Tech Center:

Related Content

Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.

Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.




Featured Webcasts
Featured Whitepapers
Featured Reports