BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

The Yin and Yang of Security and Productivity

Post by Peter McCalister March 11, 2011

If, as I discussed in one of my last posts, we can’t rely on compliance standards for anything more than setting the minimum bar for establishing our security measures, we are back to having to do the difficult trade off analysis on the real impact of security on productivity versus the benefits. And while there is no simple answer on how to do that analysis, there may be a different way to frame the problem.

Sometimes seemingly opposing things actually interact in complementary ways. The Chinese concept of Yin Yang is used to describe how seemingly contrary forces are interconnected and interdependent in the natural world, and how they give rise to each other in turn.  So is there a Yin and Yang of security and productivityCan you implement security in ways that enhance productivity? I think you can.

First, minimize the productivity impact of security by making it as transparent as possible to the end user. Ideally, they won’t have to use any extra commands, no pop ups, no extra screens to go through in order to operate securely. And if the action requested by the user is allowed, just let it happen. The Windows User Access Control slider provides a great example. If you give users the option, they will turn down the security level to avoid having to respond to an extra prompt. So if you are going to give them the authority to do certain actions after a prompt, why trouble them with the extra steps.

Second, while security controls stop people from doing bad things, these same controls can enforce best practice.  In addition to controlling actions because of the security risk we can stop people from doing things that they should not do because of the operational risk presented.  And with proper implemented controls we can do better than using  “Are you really sure you want to” pop-ups which we just click through anyway. Properly designed and implemented controls can enforce a desired way of doing things or best practice.

Finally, there is great potential in using data on what people are doing to improve productivity. Those detailed compliance logs are a gold mines of information. They can be used not just to look for patterns that indicate a security threat, but those same patterns can show where security and other procedures such as improper configurations of new systems are hurting productivity. Finding those patterens can help uncover opportunities to better train, simplify procedures, and uncover best practices that not everyone is following. And once those best practices discovered you can use controls to ensure that best practices are being followed.

Leave a Reply

Additional articles

BI-Qualys-Connector-IMG1

Getting More Value from QualysGuard Vulnerability Data with BeyondInsight v5.1

If your vulnerability assessment scans can’t produce meaningful and actionable reports, performing a scan does no good for anyone. If you’ve read my other blog posts, you know I have no qualms about stating that BeyondTrust provides the best vulnerability reporting in the industry. Ask your favorite analyst and they’ll tend to agree. Of course,…

Post by Morey Haber April 18, 2014
Tags:
, , , , , , , ,
insider-threat-fed

Mitigating Inside Threats to U.S. Federal IT Environments

Recent high-profile cases have increased the perceived risks that go along with disclosure and usage of confidential information. One of the most difficult security threats to mitigate is an attack from the inside. When an over-privileged user, such as an unhappy current or former employee, contractor, or consultant, begins navigating your network, how will you…

Post by BeyondTrust Software April 17, 2014
Tags:
, , , , ,

Are you a Target? Investigating Security Breaches with Kevin Johnson

Last week, over 1,000 IT security professionals watched as Kevin Johnson, CEO of Secure Ideas, presented his expert opinion on lessons learned from recent, high-profile retail breaches. Here’s a summary of key takeaways from the webcast plus an on-demand recording of the full, 60-minute presentation. Understanding the “why” behind attacks According to Kevin, the primary…

Post by Chris Burd April 17, 2014
Tags:
, , , , ,