Shadow IT is becoming a big problem for many organizations. What are some of things your organization do to identify and manage shadow IT?
The best way to identify is to ask the LoB heads to self disclose these applications in their area, failing which they will have to take care of any SOX audit issues by themselves(which most of the LoBs do not want to). Once these applications are disclosed, IT teams can create a risk profile around these apps, and share the same with LoB heads. The risk profile should indicate how quickly these applications have to be remediated to meet compliance factors. The rest is the standard SDLC process to help these applications meet the necessary standards and helping set up collaboration between LoB and Tech to manage these apps. Obviously you cannot solve all the shadow IT issues in a year or two, infact you will
Have to live with, it is a choice of which apps to be managed by IT and which ones to be left with business
Did you ever consider looking at a CASB tool? I would recommend looking at McAfee MVISION Cloud? This tool is amazing, it provides critical capabilities such as identifying all cloud applications/services being access through your network, it has a lot of additional capabilities for securing your network and systems.
I agree.
It is balancing act and continuous challenge with evolving technologies.
What happened was we all thought, as technologists, that information technology should be used much more pervasively and was deeply ingrained into the day to day operations of the company for years. We would say we're really missing an opportunity here but it's innovating so fast. There's so many ways of getting more benefit out of technology. And then we kind of woke up and realized that functions went off and did what we said out loud. They're using technology in ways that meet their immediate interest.
It is a very good way to control the paid services, but how about the free cloud services (e,g., Dropbox, LinkedIn...), how would you control find those and control (approve/not approve)?
The best way to overcome shadow IT is to stop working in isolation from the business. Connect with them and start asking what they need, and then delivering on it, even if that means taking over their Shadow IT elements - it's going to save you more time than trying to shut it all down
You're both there trying to achieve the same outcome for the overall business, keeping an 'us and them' mindset doesn't do that.
Agreed, sometimes too much controls hinder creativity and could result of your organization losing their competitive advantage. Protect you sensitive information assets and PII data in a secure enclave (firewall), using strict access controls, 2f.
- there's a differentiation between shadow data and shadow IT. As you say, protect your sensitive information as it is an asset, but don't worry about shadow IT so much
Absolutely agree, it is critical that organization address it also.
Content you might like
An excellent language that has a bright future21%
A great language that enabling rapid MVPs, but not full products53%
Somewhat sustainable but should look to be sunset22%
A dead or dying technology5%
Once a day28%
Once every few days34%
Once a week17%
Once a month10%
Once a year5%
Never5%