Are Your IT Folks Snooping Your Protected Data?

In a survey of IT professionals published Wedneday, 67% of respondents admitted having accessed information that was not relevant to their role, and 41% admitted abusing administrative passwords to snoop on sensitive or confidential information.

By Ellen Messmer
Wed, July 07, 2010

Network World — In a survey of IT professionals published Wedneday, 67% of respondents admitted having accessed information that was not relevant to their role, and 41% admitted abusing administrative passwords to snoop on sensitive or confidential information.

Slideshow: Quiz: Do You Know IT Security?

The survey, entitled "Trust, Security and Passwords," was conducted by security firm Cyber-Ark Software, which earlier this spring asked 400 IT professionals from the United States and the United Kingdom several questions about snooping. The firms says the survey was conducted during the RSA Security Conference 2010 and the Infosecurity Europe 2010 Conference.

What would your ultimate network security look like?

About 245 IT professionals participating in that survey answered the questions: "Have you ever accessed information on a system that was not relevant to your role?" and "Have you or any of your colleagues used the admin password to get at information that is otherwise confidential or sensitive?"

Slideshow: When Rogue IT Staffers Attack: 8 Organizations That Got Burned

It turns out those unauthorized practices involving snooping at data were fairly common, and in addition, 56% of the survey respondents in the United Kingdom and 74% in the United States believed they can get around any controls that have been put in place to monitor privileged access.

However, despite the rise in confessed snooping since Cyber-Ark conducted a similar survey last year, fewer IT professionals this year said they believe they can circumvent controls.

When asked about snooping in their organizations, 54% of the respondents indicated they regarded the IT department as the department far "more likely to snoop around the network and look at confidential information" in comparison to those in other occupations, including accountants, managers, secretaries, marketing, sales and human resources.

Out of 392 respondents, a small number even said they would likely abscond with a database, financial reports, R&D plans or the CEO's password if they were told they "were going to be fired tomorrow".

Read more about wide area network in Network World's Wide Area Network section.

Originally published on www.networkworld.com. Click here to read the original story.
This document is aimed at those looking at data center builds, upgrades, or consolidation. It provides an introduction to some of the new security challenges of such environments and provides recommendations for implementing security in next-generation data centers.
This editorial brief addresses the disconnect between security and operations teams and the need for IT operations teams to address security and risk management.
The McAfee virtual patching solution provides a layered approach to security risk management, while adding the ability to apply a virtual patching strategy to your existing change-management process.
Learn more about Gartner's evaluation of network IPS that places McAfee in the leaders' quadrant. Deep inspection network-based intrusion prevention continues to be a due-diligence security control.
The topics span attack categories, trends and priorities, with a short synopsis of the topics, various use cases, key concepts, and providing references to our Security Connected Reference Architecture.
With cybercrime on the rise, McAfee and Intel researchers believe that we need to re-envision how to detect and block stealthy malware.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
Big Data-it has the potential of transforming a business. In the case of Klout, a social networking analytics site, big data is the heart of the business. Klout processes and analyzes billions of user data signals every day-from Facebook, Twitter, LinkedIn, blogs and more. How do they do it? Gain valuable insights from David Mariani, vice president of engineering for Klout.
Date: February 29, 2012
Time: 1:00 PM EST

Seasoned IT managers know from experience that in many cases the bulk of the cost of an IT solution is incurred after the sale. Issues can range from sizing and skill development, to committing significant resources installing, deploying, managing, and supporting a complex assortment of hardware, software, and networking.

With the Oracle Database Appliance, you can eliminate the time, risk, and costs often associated with building, implementing, and maintaining a high-availability solution for your users and customers. Plus it's based on Intel Xeon processors to ensure a high level of performance and scalability.

Attend this Webcast to discover how the Oracle Database Appliance can help you increase your ROI by:
* Reducing deployment time from weeks to hours
* Simplifying ongoing maintenance and support
* Benefitting from the highest levels of availability
Today's workforce is truly mobile. At the office, from customer sites, even at home or in a hotel - their connectivity and application performance needs remain the same. But even though their requirements don't change, the challenges in meeting their expectations do.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center