Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

7/24/2012
12:38 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

HiSoftware And AIIM Survey Highlights Gaps In SharePoint Content Security

The struggle between the open-nature of SharePoint and the need to secure sensitive data is clear in the reactions from respondents

Boston, MA, July 24, 2012 – With SharePoint quickly taking over as the primary repository for enterprise content, HiSoftware and AIIM teamed up to examine exactly what information gets stored in the SharePoint repository and how companies secure this data. Overall, 82% of respondents said that they regularly store or access secure content through their SharePoint implementation, yet 57% worry that SharePoint doesn’t meet their security and compliance needs. In fact, 13% of those in large organizations call SharePoint “a disaster waiting to happen.”

The frightening conclusions are captured in the paper titled, "SharePoint Security – A Survey on Compliance with Recommendations for Improvement," available for download on the AIIM website.

The paper, which is based on a survey of AIIM members that use SharePoint, focuses on how organizations address various aspects of SharePoint security including: protecting documents from being accessed by the wrong users; managing audit trails; adhering to compliance standards and tracking a document’s train of custody.

SharePoint Struggle: Balancing Compliance, Security and Collaboration

The struggle between the open-nature of SharePoint and the need to secure sensitive data is clear in the reactions from respondents, such as: "If you want compliance, don't use SharePoint," and "Our organization lacks understanding of what's actually in SharePoint, from a sensitive/regulated information perspective."

"The issues at hand are staggering when you take a deeper look at the numbers," said David Jones, market analyst at AIIM International, who authored the report. "SharePoint security is on the edge of being out of control. An alarming 70% of organizations say that they rely on humans to manage security vulnerabilities, even as they continue to drop sensitive information such as financial and HR data into SharePoint."

"More than 60% of Microsoft Enterprise customers use SharePoint, and it has emerged as the central repository that organizations use to put all sorts of data and information for easy internal access," said HiSoftware CEO Kurt Mueffelmann. "But this access comes with challenges, and that's the struggle we see in these survey results. Companies generally have governance rules and know what should and shouldn't be shared, but because SharePoint grew so rapidly, they've been unprepared to deal with the platform’s security risks.”

Among the key findings from the survey:

· 82% use SharePoint to access or store secure content.

· Over half (57%) are worried about SharePoint not meeting their security/compliance requirements.

· Just over half (51%) are using encryption on content. However, it is not being deployed consistently across platforms with adoption no higher than 17% for any particular platform.

· Only 38% of organizations feel that their SharePoint implementation actually does satisfy their information security needs.

· 13% of large organizations feel that their SharePoint security is “a disaster waiting to happen.”

· Over 20% of those surveyed store military and criminal content within SharePoint.

· Only 24% of organizations have security concerns about allowing mobile access to content.

Demographics of the Survey

HiSoftware and AIIM surveyed 263 individual members of the AIIM community about the work they do with SharePoint and the security protocols they have in place. The sample represented companies of all sizes with most (40%) respondents from large organizations of more than 5,000 employees. Another 37% of respondents were from organizations with between 500 and 5,000 employees and 24% were from small to mid-sized organizations. More than half of the respondents were US based, with Canada and Europe making up the rest of the audience.

HiSoftware is premiering the survey results at SPTechCon Boston. The company can be found in the Exhibit Hall in Booth 406.

About AIIM

AIIM (www.aiim.org) is the global community of information professionals. We provide the education, research and certification that information professionals need to manage and share information assets in an era of mobile, social, cloud and big data. Founded in 1943, AIIM builds on a strong heritage of research and member service. Today, AIIM is a global, non-profit organization that provides independent research, education and certification programs to information professionals. AIIM represents the entire information management community, with programs and content for practitioners, technology suppliers, integrators and consultants.

About HiSoftware

HiSoftware is a leading provider of content-aware compliance and security solutions for the monitoring and enforcement of risk management and privacy guidelines across digital environments. The company’s solutions provide a data governance platform for content management and collaboration processes that support corporate and brand integrity, site quality, accessibility and confidentiality for public websites and portals, as well as intranets and SharePoint sites. HiSoftware’s customers include some of the largest US and international government agencies, as well as Global 2000 companies. For more information, visit http://www.hisoftware.com.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: George has not accepted that the technology age has come to an end.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-26814
PUBLISHED: 2021-03-06
Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service sc...
CVE-2021-27581
PUBLISHED: 2021-03-05
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-28042
PUBLISHED: 2021-03-05
Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution.
CVE-2021-28041
PUBLISHED: 2021-03-05
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVE-2021-3377
PUBLISHED: 2021-03-05
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.