[ insider_reports_insider ] Over Half Of Employees Work Around IT Security Policies
Mike Sachoff Staff Writer
2008-10-14
Insider Reports RSS Feed
Employees are aware of the restrictions put in place by their corporate IT departments, yet many often work around these controls to get their jobs done in a timely matter, according to a new survey from RSA, the security division of EMC.
 | | Over Half Of Employees Work Around IT Security Policies |  | The majority (94%) of employees are familiar with their organizations IT security polices, yet 53 percent have felt the need to work around IT security polices in order to get their work done.
Over half (64%) regularly send work documents to their personal email address in order to access and work on them from home. The majority (89%) frequently conduct business remotely over a virtual private network or webmail. Over half (58%) sometimes access their work email via a public wireless hotspot.
"Data loss prevention is a key concern for those in charge of today's corporate networks and information assets. However, with the sheer portability of information that we have today, it is essential that that data is governed not by the whims and day-to-day actions of your employees, but rather by pre-determined policy and subsequent controls," said Tom Corn, Vice President, Data Security, at RSA.
"In this way, organizations can prevent sensitive information from being written to a USB flash drive in the first place - or at least mandate that it is encrypted."
RSA recommends that access to highly sensitive data should be given to only those who need it, and in some job functions access to only specific areas within the information infrastructure are necessary.
"It remains clear that businesses need to take a layered approach to security to help mitigate the insider threat and keep data safe," said Christopher Young, Senior Vice President at RSA.
"As such, it is important for any organization to know who has access to your information; control access through policy; monitor for suspicious activity to verify user identities; create and enforce data security policies and controls; and transform real-time event data into actionable compliance and security intelligence."
About the Author:
Mike is a staff writer for WebProNews. Visit WebProNews for the latest ebusiness news.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|