Analytics
11/14/2012
08:10 PM
Don Bailey
Don Bailey
Products and Releases
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Forrester Survey: Wary Enterprises Still Place Sensitive Data In The Cloud

User provisioning and SSO/Web access management the two leading access-control priorities for enterprises

BOULDER, Colo., Nov. 14, 2012 - Symplified, the Cloud Identity Company, today released new research that shows one third of enterprises place highly sensitive data in the public cloud even though most are wary of the implications on security and other business processes. The findings -- from an independent August 2012 commissioned study conducted by Forrester Consulting on behalf of Symplified -- of US enterprise IT security managers, also found that nearly half of respondents do not think their existing identity and access management (IAM) infrastructures will be able to support cloud applications and provide single sign-on (SSO).

According to the study entitled "Access Management for the Extended Enterprise: A Timely Challenge," while most enterprises are concerned about exposing data to the cloud, nearly a third of them already place highly sensitive data like regulated financial (34%) and healthcare information (29%) in SaaS apps. As for their preferred method for consuming cloud security, the top two choices - embedded in the cloud service (23%) and third-party on-premise solution (20%) - were evenly split.

"The data collected shows that IT managers are living with a gap between cloud usage and corresponding cloud security. As solutions for managing cloud access mature, we anticipate IT departments will feel corresponding pressure to improve the fundamental processes of identity management and access management within their own organizations," said the study. "They must increasingly support business owners in a drive to take advantage of cloud-enabled and mobile-enabled business partnerships - and their ability to execute will be significantly affected by the ability of their IAM systems to adapt."

Key Survey Findings

Forrester Consulting identified the following key IAM trends:

. User Provisioning (61%) and SSO/Web Access Management (53%) are the two leading access control priorities for enterprises

. 52% of enterprises are very concerned or somewhat concerned that their attestation and access request processes won't fit with their cloud IAM solution

. 52% were very concerned or somewhat concerned that their infrastructure is not up to date to support cloud IAM protocols

. 48% of respondents were very concerned or somewhat concerned that their organization needs SSO to non-SAML or non-federated SaaS apps

. 38% were very concerned or somewhat concerned that their existing IAM infrastructure is incompatible with their cloud IAM solution

"This survey reveals that enterprises recognize the need for cloud identity and access management, but they're concerned about their ability to integrate these capabilities within existing infrastructures," said Brian Czarny, vice president of marketing for Symplified. "It's also clear that supporting non-SAML apps is a big challenge, and that organizations want the ability to choose between cloud-based and on-premises security options."

Symplified will host a free webinar presenting an in-depth analysis of the Forrester Consulting findings featuring Forrester Research, Inc., principal analyst Eve Maler. The webinar will take place on Thursday, Nov. 29 at 11am Mountain Time. To register, click here.

About Symplified | The Cloud Identity Company

Symplified provides seamless single sign-on, identity and access management services to help enterprises around the world safely and securely connect users to cloud, web and mobile applications. Symplified is headquartered in Boulder, Colorado and can be found on the Web at www.symplified.com. Don A. Bailey is a pioneer in security for mobile technology, the Internet of Things, and embedded systems. He has a long history of ground-breaking research, protecting mobile users from worldwide tracking systems, securing automobiles from remote attack, and mitigating ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2014-2716
Published: 2014-12-19
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.