|
Gartner estimates that 70 percent of security incidents that actually cause loss to enterprises rather than mere annoyance involve insiders. This finding should surprise no one. Insiders create an enterprise's products and deliver its services, and efficient access to sensitive information is essential to its efforts to bring profitable products to market quickly and competitively. Nonetheless, enterprises must find the balance between completely open internal access and overprotective security that hurts business. Enterprises can achieve this balance by:
- Conducting background investigations before employees are hired. Background investigations should be required for all employees including system and security administrators who will have access to sensitive information.
- Enforcing "need to know" policies. Consolidated access management architectures should be deployed to allow server and database access only to employees who require it for legitimate business purposes. Audit and reporting tools should be used to review privilege escalation actions.
- Using acceptable-use enforcement technology. Enterprises should "trust but verify" by using tools from providers such as Niksun, SilentRunner and Vericept and that enable them to spot policy violations or illegitimate access to sensitive information within vast amounts of internal traffic.
Analytical Source: John Pescatore, Gartner Research
Recommended Reading and Related Research
(You may need to sign in or be a Gartner client to access all of this content.)
|