Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/15/2010
08:23 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Industry Poll Shocker: Employees Bypass IT Policies

A poll released today by Harris Interactive found that a good portion of workers admit that they knowingly violate IT policies so that they can get their work done. My take: those workers that didn't admit that they violate corporate compliance and security policies are liars.

A poll released today by Harris Interactive found that a good portion of workers admit that they knowingly violate IT policies so that they can get their work done. My take: those workers that didn't admit that they violate corporate compliance and security policies are liars.According to the poll of 1,347 employed adults ages 18 and up showed that 12 percent admitted to breaking policy. The poll was conducted online by Harris Interactive between February 2 and 4, and funded by mobility service provider Fiberlink.

Here's the quote from CEO of Fiberlink, from the company's statement announcing the poll:

"We see this as a mobility wake-up call for all IT managers," said Jim Sheward, CEO of Fiberlink. "IT departments nationwide spend a lot of time and money on their compliance, usage, and access policies, but they only work if people follow the rules. Without extensive and effective compliance tools that ensure that IT policies are being followed, companies could face dangerous breaches that include the loss of sensitive data, competitive intelligence, or customers' private information."

First, these poll results could apply to just about any IT security and policy compliance issue: passwords, encryption, rogue wireless access points, shutting down anti-malware when it becomes inconvenience, and the list goes on. But Fiberlink sells mobility management services, so that's their spin. Too bad the poll (or at least it wasn't communicated in the release) didn't focus on actual mobile compliance issues.

Second, enterprises need to spend on the controls that make the most sense for their tolerance to risk and need to mitigate that risk.

Third, Sheward was too tame in one of his remarks: enterprises that rely too heavily on their employees to make the right decisions when it comes to security and compliance will lose sensitive data, intelligence, customers' private information, or suffer some significant incident. It's really just a matter of time.

I think the 88 percent of respondents who said they don't bypass policies to get work down are either lying outright, or are fooling themselves. Who hasn't broken a corporate policy to expedite workflow?

Such things could include using a simpler password that is more easily remembered, or even writing down a complex password on paper. It could include copying unencrypted data to a USB drive, using home PCs to work on company files, using wireless connections with their corporate issued notebook. Users who click on links or open attachments from people they don't know, or access certain Web sites are probably violating policy. And the list could go on indefinitely. While few break all of the rules all of the time, fewer still follow all of the rules all of the time.

That's why companies that rely on end users to do the right thing and always follow security policy are heading for trouble. A certain percentage of users, no matter how small it is, will click on links they shouldn't, they'll visit Web sites they shouldn't, they'll use passwords they know are inadequate, and they'll check e-mail from the corner coffee shop wireless connection.

All of those actions jeopardize not only the end user doing them, but the security and compliance posture of the entire organization. And enterprises that don't use technological controls to thwart these behaviors are just asking for trouble.

For my security and technology observations throughout the day, follow me on Twitter.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Browsers to Enforce Shorter Certificate Life Spans: What Businesses Should Know
Kelly Sheridan, Staff Editor, Dark Reading,  7/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17366
PUBLISHED: 2020-08-05
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate...
CVE-2020-9036
PUBLISHED: 2020-08-05
Jeedom through 4.0.38 allows XSS.
CVE-2020-15127
PUBLISHED: 2020-08-05
In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flip...
CVE-2020-15132
PUBLISHED: 2020-08-05
In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that th...
CVE-2020-7298
PUBLISHED: 2020-08-05
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.