- 1
- 2
- < previous
The issue isn't just control over passwords, but also over documentation relating to configurations and changes. Often in situations such as this, "requests for access, passwords and documentation are frequently taken as hostile acts by those that have been holding the keys to the kingdom," he added. "In my experience I have encountered this type of situation on more then one occasion," he said. In one incident, a mainframe systems programmer had to be fired for changing access rights because he disapproved of others' activities on the system, Michael said. In another case, the individual resigned when he "realized that the pressure to follow processes and procedures was not going to go away despite the protesting," Michael said.
These practices persist due to lack of resources and prioritization, said Richard Gorman, CEO of Vormetric, a vendor of database security and encryption products. "For many organizations, security is not a mission-critical priority until it has been breached," Gorman said. As a result, it is not unusual to find many companies handing over control of entire networks and systems to one individual. "There is no valid technical reason to do this," and it is something that can always be avoided. Nonetheless, it is "surprisingly common."
Especially in smaller and medium-sized companies, control is vested in a single individual in order to more cost-efficiently troubleshoot problems and take care of daily administrative tasks such as resetting passwords, said Raj Rajamani, product manager at Solidcore Systems, a vendor of change management products.
"If you have one person serve as an administrator, then have another person audit the administrator, and have yet another person audit the auditor, you get into a costly and time-consuming cycle of inefficiency," he said. Tools are available to do this sort of auditing, but often the process can be more of an impediment than a benefit, he said.
"Single points of failure are always bad," said John Pescatore, an analyst with Gartner. "There should never be one person who is the only person who knows the configuration or the password." Companies need to make sure there are at least two if not three people who share the knowledge of network configurations and server configurations. "As a minimum, require it to be documented and stored somewhere if personnel limitations say you can't have personnel with overlap," Pescatore said.
- 1
- 2
- < previous
Latest on Passwords
- Access vendor GridSure uses patterns to remember PINs
- Good security in recessionary times
- Tough economic climate can heighten insider threat
- Poll: Two thirds of users never change passwords
- IBM, Secret Service, others study identity/cybercrime issues
- Strange account management at Amazon
- Crimes, anonymity and the Net
- IBM vets ID management, access control on own systems
- Top 10 ways collaboration, mobility amplify data leakage dangers: Cisco study
- After password glitch, Firefox patch due next week
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
TechWorld Jobs (beta)
Recent Jobs
Whitepapers
- Discover the advantages of an open architecture multi-vendor network solution
- How to Beef Up Your Sales Pipeline
- Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
- Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
- Choices in Storage Architecture for Oracle Environments
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- A Novell approach to business
- An open storage stack? I like the sound of that
- The mobile clone wars: fighting for a better phone experience
- Stopping the "Clean Feed"
- Identifying web platforms
- Clean Feed ‘not technically possible’
- No Clean Feed - well duh!
- Conroy's content cops still on the cards
- Will open source ruin the economy? Please help
- Linux kernel 2.6.27 is out!
Recent comments
- A real alternative?
18 hours 54 min ago - Hello this is Brianna
2 days 4 hours ago - Turn any PC into a media center
2 days 18 hours ago - How About the Correct Title?
3 days 9 hours ago - who are you kidding?
3 days 14 hours ago - Seriously, how much did they pay for this advertisement
5 days 5 hours ago - SF Bay Area - free Seminar on Enterprise Cloud Computing
5 days 8 hours ago - video conferening but not telepresence...
5 days 15 hours ago - SAMSUNG OLED 40" TECHNOLOGY
6 days 23 min ago - What was the question again, oh well this was prepared earlier
1 week 1 day ago - Worldwide broadband prices continue to drop which means ? in AU
1 week 1 day ago - Not a Problem Here in Australia and New Zealand
1 week 3 days ago - Clear the air
1 week 4 days ago - Tabbed browsing, Quick Find,
2 weeks 1 hour ago - Microsoft details plans for new social bookmarking tool
2 weeks 1 day ago - There is a 3rd party tool
2 weeks 3 days ago - Demise of Windows
2 weeks 3 days ago - new OS
2 weeks 3 days ago - Re: Favicon
2 weeks 4 days ago - Multi Camera Kino
2 weeks 4 days ago



