BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Accident Prone Annie Requires New Policies For Control

Posted August 19, 2011    Peter McCalister

I introduced you to Accident Prone Annie as an archetype for the type of insider villain who may already be infiltrating your extended enterprise a couple of weeks ago and guess what? Almost every day I see an article that represents “Dave” as manifesting in another company with some measurable harm that was newsworthy.

The latest article I found was at eweek.com and reported “Data Breaches Force Enterprises to Revise Privacy Policies: Gartner” and went on to say “As a result of recent high-profile data breaches and various changes in technology, organizations are expected to revise privacy policies by the end of next year, Gartner researchers predict. As cloud computing and location-based services proliferate, organizations are grappling with the privacy implications of having data reside outside corporate control, Gartner said in its latest report released Aug. 8″ The article also went on to report “More than half of companies will tweak the policies they already have to bring them up-to-date with new technologies and computing models, Gartner said. Data breaches ranked high on the priority list because they affect so many aspects of the business. But preparing for and following up on breaches was “straightforward,” and privacy officials should not be spending more than 10 percent of their time dealing with data breaches, according to Gartner.”

Ultimately what is becoming recognized is that the average employee can and will make mistakes on a daily basis without tighter guidelines, policies and technology to prohibit regulatory, governance or compliance mistakes.

Leave a Reply

Additional articles

Dark Reading

2014: The Year of Privilege Vulnerabilities

Posted December 18, 2014    Chris Burd

Of the 30 critical-rated Microsoft Security Bulletins this year, 24 involved vulnerabilities where the age-old best practice of “least privilege” could limit the impact of malware and raise the bar of difficulty for attackers.

Tags:
, , , , ,
dave-shackleford-headshot

Looking back on information security in 2014

Posted December 16, 2014    Dave Shackleford

Dave Shackleford is a SANS Instructor and founder of Voodoo Security. Join Dave for a closer look at the year in security, and learn what you can do to prepare for 2015, with this upcoming webinar. 2014 has been one heck of an insane year for information security professionals. To start with, we’ve been forced…

Tags:
, ,
patch-tuesday

December 2014 Patch Tuesday

Posted December 9, 2014    BeyondTrust Research Team

This month marks the final Patch Tuesday of 2014. Most of what is being patched this month includes Internet Explorer, Exchange, Office, etc… and continues a trend of the greatest hits collection of commonly attacked Microsoft software. Probably the one thing that broke the mold this month is that for once there is not some…

Tags:
,