Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

12/14/2007
12:51 PM
Commentary
Commentary
Commentary
50%
50%

Office Workers Know About Your Security Policy. But Are They Following It?

Hey IT managers, your office workers might say they are following security procedures. But get someone to ask them that question anonymously. Their answers might surprise -- and upset -- you.

Hey IT managers, your office workers might say they are following security procedures. But get someone to ask them that question anonymously. Their answers might surprise -- and upset -- you.RSA, the security division of EMC, recently published a survey tantalizingly titled, "The Confessions Survey," thanks to the way the research was conducted, in on-the-street interviews, providing its respondents with anonymity. About a third of the respondents were from small to midsize companies.

According to eWeek, "53 percent of respondents who work for the private sector access work e-mail via a public computer such as at an Internet caf, airport kiosk, hotel or the like."

Moreover, "sixty-eight percent of enterprise workers leave work carrying a mobile devicesuch as a laptop, smart phone or USB flash drivethat holds sensitive job-related information, including customer data, Social Security numbers or company financials."

The kicker is that in response to the survey question: Are you familiar with the IT security policies of your company?, a full 81 percent of business workers answered yes. Furthermore 69 percent of business workers answered yes to the question: Does your company follow training about the importance of following security best practices?

InformationWeek's John Soat flips the percentage and focuses on the 31 percent of those companies that do not provide the necessary training on the significance of following their security practices. While that is almost a third, it doesn't account for all those employees who are familiar with their company's security policies, know about their importance, and continue to flout those rules.

Perhaps that can be explained in the employees' answer to this question in the survey: "Do you ever feel the need to work around your company's established security policies and procedures just to get your job done?" A full 35 percent of business workers said yes.

Obviously security policies need to be implemented and enforced in small and midsize businesses but Soat's quote from RSA acknowledges that there is also a working reality and calls on IT managers to take that into account when establishing security policies:

"Organizations can mitigate this risk by developing information-centric policies that acknowledge and align with the needs and realities of the business. Once such policies are in place, companies should constantly measure actual user behavior against established policy and use what they learn to inform smart policy changes that minimize risk and maximize business productivity. When security is as convenient as possible for end users, they are less likely to work around security policy."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27569
PUBLISHED: 2021-05-07
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet. This information is sent in cleartext and is not protected by any authentication logic.
CVE-2021-27570
PUBLISHED: 2021-05-07
An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected by any authentication logic.
CVE-2021-27571
PUBLISHED: 2021-05-07
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic.
CVE-2021-27572
PUBLISHED: 2021-05-07
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set.
CVE-2021-27573
PUBLISHED: 2021-05-07
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no prior authorization or authentication.