July 06, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Print this article    Email this article    Talk Back!    Write to Editor

Study: Companies Open to Insider Threat Breeches

03/05/2007

According to a new study by privacy and information management research firm the Ponemon Institute, nearly 60 percent of US-based businesses and government agencies believe they are unable to effectively assess or quantify “insider threat” risks within their organizations – leaving them open to privacy breaches, failed audits and potential fraud or misuse of data.

ADVERTISEMENT
Our Popular Webinars
BPM for Financial Services
Roundtable Discussion: Open Source Market Update
Evolving Security Architectures and SOA for Better Business Collaboration
Getting Started with BPM
Roundtable Discussion: MDM's Role as a Critical Enabler for SOA
More Webinars

ebizQ received the following:

And although more than 70 percent of respondents confirm that identity compliance activities are strategically important, 58 percent still rely on manual processes to audit and control user access to critical enterprise systems and data resources.

Commissioned by SailPoint Technologies, the Survey on Identity Compliance examines the responses of more than 600 US-based senior information security professionals, pointing to inefficient processes, insufficient data and the lack of collaboration between business and IT groups as the leading causes of risk across the enterprise.

Analysis of the survey suggests that despite healthy budget allocations, the state of identity governance, risk management and compliance initiatives remains a serious challenge. Key findings include:

  • 71 percent of respondents confirm that identity compliance activities are strategically important, resulting in an average of 28 percent of total IT compliance budgets being earmarked for such initiatives.


  • 64 percent of respondents say they have deployed an identity and access management (IAM) solution, a category that includes access control, password management, provisioning and role management. Nevertheless, almost 60 percent of respondents say their companies are unable to effectively focus IAM controls on areas of the greatest business risk.


  • This limitation is viewed as severe: over 80 percent of respondents either strongly agree or agree that risk should be a determining factor in driving identity compliance activities.



Respondents cite numerous inefficiencies in their organizations’ IAM compliance processes:

  • 58 percent use mostly manual methods.


  • 87 percent employ a decentralized strategy.


  • 51 percent take a detective (or reactive) approach.



Although findings show that responsibility for identity compliance is shared across business, IT and audit/compliance groups, collaboration among them is very weak. 42 percent of respondents say that collaboration rarely occurs, while another 23 percent say it never occurs.

“Our findings point to a number of barriers preventing the implementation of effective identity management and proactive safeguards for securing sensitive corporate data against insider risk,” said Dr. Larry Ponemon, chairman and founder, Ponemon Institute. “In order to assess risk, and identify and address identity management shortcomings, organizations must have access to data and appropriate coordination across business units. Our research shows that, for too many companies, this is simply not happening.”

“As the complexity of identity management has increased, so have the inherent risks, media attention and public scrutiny associated with corporate compliance initiatives,” said Jackie Gilbert, vice president of marketing and founder of SailPoint. “SailPoint helps companies focus compliance efforts on the greatest areas of business risk in the organization, with cross-disciplinary involvement from business, IT and audit groups. Our goal is to give organizations a sustainable approach to compliance that is cost effective, automated, and systematically reduces risk exposure.”


More Top Stories
SQL Injection Rears Its Ugly Head Again Gold Club Protected
Data Warehouses and Disaster Recovery Gold Club Protected
Expect the Unexpected with Data Security Gold Club Protected
Is Big the New Small in Application Security? Gold Club Protected
Doing Risk Management Right Gold Club Protected
Defending Against the Cross-Site Scripting Attack Gold Club Protected
More Top Stories
Related News
MessageLabs Launches Email Continuity Service
StarVest Partners Acquires IRON Solutions
Valicore Debuts vCoreServer Security Appliance for Embedded Systems
More News
Print this article    Email this article    Talk Back!    Write to Editor
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Changing Tires on a Moving Car
Case studies and solutions for governing the continuous evolution of complex SOA systems

Date: Jul 15, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Roundtable Discussion: MDM's Role as a Critical Enabler for SOA
Date: Jul 16, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  BPM Done Right
Start your BPM project by measuring your current performance. Discover “lessons learned” to succeed with BPM and achieve core business goals. Learn More
ebizQ also recommends
 Optimal Service-Parts Management: Part One
 The Geek Gap: Do Suits Care?
 Collaboration and Social Media <i>Taking Stock of Today's Experiences and Tomorrow's Opportunities</i>
 Mitigate Risk with Security Assessments
 Marketing Insights - Making Trade Promotion Pay Off
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map

Live Chat