Risk
8/30/2010
01:13 PM
Connect Directly
RSS
E-Mail
50%
50%

IT Security Unleashes Employee Complaints

Protecting enterprise data and systems while maintaining employee productivity is a delicate balance for CIOs, finds Robert Half survey.




Slideshows: 12 CIOs' 'Career Killer' Pet Peeves
(click for larger image and for full photo gallery)
For 12% of CIOs, hearing complaints from employees over IT security measures -- specifically, limits on their access to certain types of websites or networks while using the office network -- is a common occurrence. Meanwhile, 29% of CIOs say such gripes are at least "somewhat common."

The numbers come from a survey of more than CIOs, selected randomly from companies in the United States with 100 or more employees, conducted by staffing firm Robert Half Technology.

"There will always be employees who feel IT security policies are too restrictive," said John Reed, executive director of Robert Half Technology, in a statement. "But in most situations, robust information security measures are necessary to protect sensitive data and an organization's network integrity from increasingly sophisticated threats."

On the other hand, said Reed, if too many people are complaining, then maybe it's time to reevaluate whether an organization's security policies have come down on the wrong side of the security-versus-productivity equation.

Rather than worrying whether their security policies are too restrictive, however, many organizations have a more fundamental problem: they lack any security policies, or else mechanisms for automatically enforcing those policies.

The result in either case is the same: employees often take their chances, ignoring any rules that they think are slowing them down, such as social networking restrictions or file transfer rules. According to numerous studies, when it comes to flouting security policies, IT personnel can be amongst the worst offenders.

But if corporate security or web access rules are cramping your style and making it harder to do your job, Reed recommends speaking up. "Some policies may simply be outdated and no longer make sense," he said. "Asking someone in your organization's IT department why access is restricted is often one of the quickest ways to resolve an issue."

If policies aren't judged to be outdated, he suggests talking up the business reasons for why they should change. "If employees can't access a client's website or a professional networking site that can generate business, it will probably be an easy case to make," he said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0993
Published: 2014-09-15
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2014-2375
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

CVE-2014-2376
Published: 2014-09-15
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2377
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

CVE-2014-3077
Published: 2014-09-15
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
CISO Insider: An Interview with James Christiansen, Vice President, Information Risk Management, Office of the CISO, Accuvant