RT @zdnetasia: Gartner: Mobile CRM gives better ROI than social. http://t.co/nTgj44H8
8 minutes ago by Oystor_Tweets on twitterZDNet is available in the following editions:
Growth in data volume and ease of access among causes for increasing security breaches, warns a security expert, who adds that flexibility of controls can mitigate threats.
stree naidu, wikileaks.org, imperva, asia, information technology, productivity software, word processing software, technology, software, science and technology
With increasing ease of access to corporate data, organizations are in danger of "breaches" in the form of files, rather than database records, warned security vendor Imperva, adding that the number of affected companies is set to rise.
As more and more sensitive data gets disseminated as unstructured content, hackers may seek to take advantage of the loopholes, and make away with confidential data for financial or personal gains, Stree Naidu, Imperva's Asia-Pacific vice president, told ZDNet Asia in an e-mail interview.
"While most business applications use structured storage such as databases to maintain and process sensitive and critical data, users are constantly creating and storing more unstructured content, based on the information taken from these systems," he said.
Such information include data stored in excel spreadsheets, presentations and medical lab results sent as letters to patients. However, it is not merely the transfer of the information that is opening up loopholes and opportunities for unauthorized access, Naidu explained.
The documents do not actually need to be sent anywhere for a threat to exist. What we've observed, and the recent WikiLeaks incidents have shown, is that data is accessible by too many people within the business--people who do have a legitimate need for access, despite strict company policies," he pointed out.
Therefore, reducing access rights to a business need-to-know level and monitoring access activity are some ways to mitigate the risk.
Furthermore, with data volume increasing at 60 percent every year, increased sharing of data, as well as data retention policies, are also contributing to the threat of security breaches, Naidu said.
The situation is further complicated by the fact that files are "autonomous entities", which organizations do not have control of even with today's tools, he added. Unlike database records, which are created by pre-programmed applications, the inability to maintain control of files "may result in excessive access privileges and an inadequate audit trail of access to sensitive information".
Cloud-based software such as Google Docs and Jive, and internal document management systems such as Microsoft's SharePoint or EMC's Documentum becoming part of enterprise IT, have also upped the attack surfaces and, therefore, risk of threats.
The Wikileaks incident last year was a clear indication that "massive leakage and compromise of sensitive information is indeed becoming a clear and present danger", according to Naidu.
Another case of high-profile breach involved a former Goldman Sachs employee, who stole source code used for a proprietary high-frequency trading program, by using his desktop to upload the code to a server based in Germany, Naidu noted.
The bank identified the misconduct after observing large amounts of data leaving the servers, which led to the rogue employee's arrest.
With these in mind, Naidu said organizations ought to budget and plan for the next generation of file access monitoring and governance tools to reduce the risk of file exposure. Some key characteristics to take note of include:
The executive also advised that enterprises be constantly on the lookout as hacking methods are always "improving and evading detection". Businesses, he urged, should increase monitoring visibility of traffic and setting security controls across all organization layers.
"A security control should understand these shifts in the hacker industry and rapidly incorporate these changes in their organization," said Naidu. "This could even include incorporating a reputation-based control, which could stop large automated Web-based attacks known to originate from malicious sources."
RT @zdnetasia: Gartner: Mobile CRM gives better ROI than social. http://t.co/nTgj44H8
8 minutes ago by Oystor_Tweets on twitterChina hits back at Pentagon report on spy claims. http://t.co/CccR4SBM
8 minutes ago by zdnetasia on twitterChina hits back at Pentagon report on spy claims http://t.co/YP380BYQ http://t.co/erFX4aVv #arcavir
8 minutes ago by V_RaV on twitterhttp://t.co/VNaZtseV China hits back at Pentagon report on spy claims: Annual report by Pent... http://t.co/TvgCi5RE http://t.co/wiqY9ktt
8 minutes ago by RavtachSolution on twitter#AntiVirus News: Mac users' indifference toward security 'worrying' http://t.co/spWS0CpU #AdAware
8 minutes ago by AdAwareFree on twitterMac users' indifference toward security 'worrying' http://t.co/BtVn1BAk
> expected! They still remember Mac vs PC ads
#infosec #news #apple
Pentagon report says China exploit US tech, conduct cyberespionage, China says it has been "unjustly criticized" http://t.co/P5wgqy6I #in
23 minutes ago by EllyZDNetAsia on twitterMac users' indifference toward security 'worrying': 59 Jakarta 10350, Indonesia In light of the recent spate of ... http://t.co/Lxgnc1wM
38 minutes ago by GoodCodeBadCode on twitterPakistan lifts block on Twitter - ZDNet Asia: Pakistan lifts block on TwitterZDNet Asia59 Jakarta 10350, Indones... http://t.co/61n85ajh
1 hour ago by semarang_photo on twitterPakistan lifts block on Twitter http://t.co/WHqoJOqm http://t.co/erFX4aVv #arcavir
1 hour ago by V_RaV on twitterhttp://t.co/VNaZtseV Pakistan lifts block on Twitter: Country restores access after briefly ... http://t.co/5gqegFWK http://t.co/wiqY9ktt
1 hour ago by RavtachSolution on twitterMac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn
1 hour ago by zdnetasia on twitterMac users' indifference toward security 'worrying' - ZDNet Asia: Mac users' indifference toward security 'worryi... http://t.co/CD9pvW08
1 hour ago by win7antivirus on twitterRT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn
1 hour ago by t_phuck on twitterI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
3 hours ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
20 hours ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
2 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
3 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.