Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Employees: Security Policies Are Unrealistic

Many say they must break rules to get their jobs done

Oct 28, 2008 | 05:36 PM

By Tim Wilson
DarkReading

Current IT security policies frequently don't reflect the reality of how employees use their computers, according to a report published today by Cisco Systems.

The report, a deeper analysis of internal threat data collected by Cisco earlier this year, indicates that many users break their companies' security policies because following those policies would prevent them from doing their jobs.

"What this says is that security policymakers need to rethink the way they are developing those policies," says Marie Hattar, vice president of network systems and security solutions at Cisco. "IT people think that users aren't following them because they are apathetic or don't understand the risks. But the users are telling us that the policies aren't realistic."

Across the globe, about 80 percent of respondents said they think IT security policies are unfair. Forty-two percent said they don't comply with policies because those policies don't align with the reality of what they need to do their jobs. More than three-fourths of IT pros said they believe their policies need more frequent updates; the majority of employees agreed.

"Employees' disregard of corporate IT policies will increase as long as the policy is too rigid or impractical to allow them to get their jobs done," Hattar says.


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)