Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Survey: Collaboration Applications Not Sufficiently Secured

Rohati Systems' survey finds collaboration applications are secured mainly by passwords

Dec 17, 2008 | 11:22 AM

By Kelly Jackson Higgins
DarkReading

A new survey shows that most organizations running collaborative applications aren't taking the necessary security measures to prevent data loss and unauthorized access to their data.

Of the 117 CIOs, CISOs, and IT executives surveyed by Rohati Systems -- mostly from financial services firms -- 78 percent say their organizations mainly use basic single sign-on and passwords for authentication to these applications, which include Web-based intranet portals, Common Internet File Systems (CIFS), and Microsoft's SharePoint server for collaboration among employees and business partners.

"We were surprised to see such a high percentage still relying on authentication" only for securing their collaboration systems, says Shane Buckley, president and CEO of Rohati, a startup formed by Cisco alumni that sells a multigigabit-speed network appliance for controlling user access to applications. "That doesn't go far enough."

More than half of the respondents run a combination of intranet portals, CIFS, and SharePoint, according to the survey.

Seventy percent say that properly securing their collaboration systems requires authorization at the document level, although 60 percent say these types of solutions are too pricey and complicated. More than 40 percent also worry that access management tools could hinder their mission-critical applications, while 73 percent say their organizations aren't taking the proper security measures to prevent unauthorized access to their data.

One challenge these organizations face is the changing face of what constitutes an employee in a collaborative environment, Buckley says. "We really don't have a real definition of who an employee is anymore as [organizations] rely hugely on contractors," he says. "Collaboration was occurring across the business internally, including full-time and part-time contractors, and also with external stakeholders like business partners and customers."

Respondents say they worry most (49 percent) about their employees getting access to data and applications in the collaborative environment that they aren't authorized to reach. Domestic contractors are their next-biggest concern (33 percent), followed by business partners (29 percent), and foreign contractors (28 percent).

Another big concern about collaboration is violation of compliance requirements, the survey found. Thirty-six percent say that's their biggest concern; 28 percent, data privacy; 18 percent, the financial impact of a data breach; and 11 percent, the loss of intellectual property.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:cxf
Published:2010-08-19
Severity:High
Description:Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
Vulnerability:libvirt
Published:2010-08-19
Severity:Medium
Description:Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
Vulnerability:libvirt
Published:2010-08-19
Severity:Medium
Description:Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
Vulnerability:libvirt
Published:2010-08-19
Severity:Medium
Description:Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
Vulnerability:libvirt
Published:2010-08-19
Severity:Low
Description:Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)