Newsletter
July 5, 2009
Search 
JUST IN
cxo_content_drill
Home
CXOtoday Storage
CXOtoday Plus
News
Industry Verticals
Tech Insight
Market Scan
Interview
CXO Lifestyle
CXO Views
Case Studies
White Papers
Editorial
Downloads
Specials
SMB Zone
TECH INSIGHT
SaaS: Opportunities and Challenges in India
Despite challenges, SaaS model is here to stay. Anita N, corporate communications, Calsoft talks about what these challenges are and how enterprises can overcome them to leverage SaaS benefits.
More...
MARKET SCAN
Broadband Internet Investment Beat Recession Blues
The urge to avoid commuting and green concerns have ensured investments in broadband Internet globally remain robust and are not pared down, finds a study.
More...
 Home > Editors Speak
Email Print View Comments   

Data Security - A Lurking Threat from Inside
By Tabrez Khan
Mumbai, Feb 08, 2008 1550 hrs IST

Enterprises today need reliable controls for safeguarding confidential information from external and internal threats and data leaks. Enterprises from sectors like BFSI are further required to notify individuals in case of breach of their personal records. Although companies adopt tough measures to prevent external data theft and any such breach or hacking attempt is promptly reported and punitive actions taken, internal data theft often goes undetected and unreported. Insider theft is a problem that CIOs are extremely wary of, as it can be one of the most difficult problems to deal with. This kind of data theft can also be the most damaging to an organization. Employees, on-site contractors and off-shore vendors can be regarded as the weakest link in the information security chain and a likely threat to security of confidential data. Preventing insider data theft can be a huge challenge for organizations. While employees have to be given direct access to crucial resources, ensuring misuse of such access is also imperative on the organization's part. Data theft by employees can be difficult to prevent because they can circumvent physical and logical access controls within the organization. According to estimates nearly 50% professionals take corporate data with them when they change jobs, by either e-mailing it to themselves or storing it on a peripheral device. In industries where majority of the data is confidential, such as in financial services companies, this kind of breach can do a lot of damage. Naturally the stakes there are high in safeguarding of confidential data. While the above theft may not be intentional or at least not intended to be malicious, the threat from disgruntled employees can be. Such employees steal to cause damage, by selling crucial data to rival companies, revealing weaknesses in IT infrastructure and corporate security policy to competitors and media, and by corrupting or deleting confidential files causing downtime to systems that could severely hamper productivity. Mobile storage devices and gadgets such as pen drives, ipods, PDAs and laptops are convenient tools to ship confidential data outside the organization. Although a lot of data theft may not be malicious, the impact of such theft can still be hurtful so preventive measures require the same kind of urgency as in the case of malicious threats. The thriving black market for stolen phone numbers, credit card numbers, and other confidential data just proves the extent to which data theft has become rampant. Understanding why users circumvent security policies is imperative. In most cases it is done to speed up work. E-mailing documents to personal mail Ids, to work from home, is one instance, while turning off anti-virus agents to avoid annoying scans is another one. Also carrying important documents on a laptop is a threat as these mobile devices often get stolen or lost. Downloading games and software or accessing Internet for shopping, travel etc can also invite threats from viruses or malicious software. To reiterate, there may not be a malicious intent involved in most data theft incidents but irresponsible behavior and unintended mistakes from users nevertheless can compromise network and data security to a great extent.

  Tags: Data Security - A Lurking Threat from Inside  
  Share and Connect   Myweb MyWeb  Newsvine.comNewsvine.com 
  Recent news in Editors Speak
 
Indian Railway Leveraging IT, But Needs to Do More
Increase IT Spend, Encourage Small IT Companies
India Can Get Better as an Outsourcing Destination
Govt. Moves Expected to Boost Economic Sentiment
Obama Alert for US MNCs, not Indian IT Cos
 
 
Comment :

Name :
Company :
City :
E-mail :
Word verification : Type the characters you see in the picture below.
 
Characters are not case-sensitive
   

Comments
Report as offensive
Good Article, I have a good product which blocks the USB drive. call me on 9871583777
-
Mohit MAAR Data Secur New Delhi
21/03/08 01:50 PM
Reply
Report as offensive
We Unistal Systems Pvt. Ltd. known as Data Security & Info-security Company in India. If you wanat to get rid of such problems then contact us.
-
Shatrughan Unistal Systems New Delhi
26/02/08 09:47 AM
Reply
Report as offensive
  Deare MR.Patel can u provide the solutions to prevent data theft ? Pls email me the details about ur software .
-
S.Jena Computer Care bhubaneswar
25/02/08 08:45 PM
Reply
Report as offensive
the note talks about the problem with no proper solution. Can someone advice a proper solution on this internal threat
-
Sandeep Bir IntelliGroup As New Delhi
18/02/08 09:01 AM
Reply
Report as offensive
  Thin clients can be designed so that no application data ever resides on the client (it is entirely rendered), centralizing malware protection and minimising the risks of physical data theft.
-
K.R.Varma Priya ltd kochi
25/02/08 02:33 PM
Reply
Report as offensive
  Dear Sir, We have software by which we can solve your problem. Please tell me your E-mail so that i can give you proper solution.
-
Mittal Patel Megastar comput Ahmedabad
25/02/08 03:08 PM
Reply
Report as offensive
We have realized this long ago and have a solution which gives complete control to SYS ADMIN over entire network and Computers on Network preventing users to copy files on removable devices like USB Drives, PDAs, CD/DVD RW. It keeps a log of files copied to and from ,locations, names of files printed by an employee also. It also keeps tabs on what kind of softwares are installed on any computer and gives an alert if any new softwares are installed on any of the PCs and can be removed from remote.
-
Bhuvnesh Thakar MEgastar Comput Ahmedabad
25/02/08 02:43 PM
Reply
Report as offensive
We really appreciate the way you have given insight. We being be Security solutions provider getting same challanges from CEO and CIO .We have deployed multiple solutions in diiferent verticle and done sucessfull poc.solutions is available based out what type of industry they are in to.
-
Pankaj Jha DATA SECURE SOL NOIDA
19/02/08 10:05 AM
Reply
Report as offensive
  Dear Pankajji, I want a solution for the KIIT University Bhubaneswar, where internal users are students. Can you suggest a solution? Great time to see you here.
-
Prof. Srikant KIIT University Bhubaneswar
22/02/08 10:13 PM
Reply
Report as offensive
I agree on the concern raised by Mr Tabrez Khan,but there is a solution for this too.One could keep a check on devices brought in by employees in office as well as have a centralized secure system for confidential data which can be accessed using rights given to the user and of course email's can also be scanned to check in data theft.This sounds difficult but using proper technology and proper security setup physically as well as using software technology one could bring down such thefts
-
Rohit D'souza Spyrotec India Mumbai
22/02/08 04:28 PM
Reply

Disclaimer
ITNation (India) Pvt. Limited and its sites: www.channeltimes.com, www.techtree.com and www.cxotoday.com provide Comments and discussion boards as a professional medium for the various businesses of the IT industry to discuss business problems. Gossip, personal attacks and unsubstantiated charges are prohibited. Messages posted on this Web site as discussion threads or Comments (Content) are solely the opinions of their creators and do not necessarily reflect the opinions of ITNation (India) Pvt. Limited or its sites www.channeltimes.com, www.techtree.com and www.cxotoday.com.
All individuals who post material to this web site are solely responsible for all Content that they upload, post or otherwise transmit via the Web Site.
ITNation cannot vouch for the authenticity of the user or company names or e-mail addresses associated with posted messages. Under no circumstances will ITNation India Pvt.Ltd. or Cxotoday.com be liable in any way for any Content, including, but not limited to, for any errors or omissions in any Content, or for any loss or damage of any kind incurred as a result of the use of any Content posted or otherwise transmitted via the Bulletin Boards.
ITNation reserves the exclusive right to edit or remove messages containing inappropriate language or other material that could be construed as libelous, potentially libelous, or otherwise offensive or inappropriate. Discussion forums, bulletin boards and chat facilities are provided by ITNation solely for the convenience of those who make use of the service. ITNation does not endorse the products and services or other offerings mentioned in messages.
TODAY'S HEADLINES
Budget 2009
ESOPs should be made
Symantec's Quorum
BI to Manage Unstructure
Barrett Gives Intel-Noki
CXO VIEWS
Lean Six Sigma Makes Biz Customer Responsive
Lean Six Sigma (LSS) is a management concept that focuses on customer needs like no other process does, says Balaji Rajagopalan, executive director-Operations and LSS, Xerox. Rajagopalan dwells extensively on the LSS concept in an interview with Tabrez Khan
More...
LATEST COMMENTS
want training in finance mgt pls contact ..
If India can't take advantage of the global ..
HELLO SIR i have got the information that ..
I WANT TO BE A AUTHORISED ALL TYPES OF TICKET ..
dear sir, i have a 2000 sq ft. space available ..
MOST POPULAR STORIES
Nandan Nilekani to Quit (2)
Budget Expectations (2)
Roshni Nadar HCL CEO (1)
Healthcare, Energy (1)
Satyam Computers is MS (1)
Copyright (C) 2009 ITNation India Pvt. Ltd. All Rights Reserved.