Improving security by removing admin rights not practical

 

Summary

Disallowing admin rights of employees' endpoint devices not realistic solution to preventing malware threats in today's self-service IT business climate, observers say.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

The removal of administrative rights to employees' endpoint devices such as desktops and laptops is not a foolproof security solution and unrealistic in today's era of IT consumerization. Rather, risk assessment of employees' job scope to determine level of admin rights given and training are more feasible options, industry insiders argued.

Tatsuya Yoshizawa, product marketing manager of Blue Coat Systems, said removing administrative rights to devices for workers may seem counter-intuitive but it is one of the more "reasonable" solutions to protect the company's data from external threats. Such a move will make endpoint security more secure and eliminates the risk of users unknowingly downloading and installing malware, he added.

That said, the Japan-based executive noted that the removal of such rights does not mean that IT administrators can stop users from accessing malicious or inappropriate Web sites or control specific operations within an application. Actions include uploading sensitive documents on a public forum or sending a customer list via their private Web e-mail clients, he explained.

Besides, for large enterprises, revoking admin rights for all employees in order to boost security could turn into a time- and labor-intensive initiative, Yoshizawa noted.

Joseph Steinberg, CEO of New Jersey-based Green Armor Solutions, chimed in, saying that even by taking away users' admin rights, plenty of problems--including malware--can still arise, he said during a phone interview.

Both of them were responding to a blog post written last month by Neil Macdonald, vice president and distinguished analyst at Gartner, in which he argued that for enterprises thinking of switching security vendors because of "malware infestations" challenges, they should first look at the option of removing administrator rights for users' endpoint devices.

MacDonald also mentioned in a blog post this May that removing administrative rights for Window users is not a "lockdown", as users can still install and execute well-written software, printer drivers, ActiveX controls and standard day-to-day Windows functions such as changing time zones or monitor resolution.

Consider business environments, security policies
While Windows-based systems may be more easily controlled through such domain policies, Ang Chye Hin, regional director of SonicWALL Southeast Asia, pointed out that other platforms will require another set of controls that may be an "unnecessary burden" for organizations with less available resources.

It will also be challenging if the organization does not have an established security management framework that covers the objectives of the organization's security strategy, rules and policies, he added. This framework would look into what rights should be removed or granted, exceptions to the rule and developing user awareness programs, he explained.

"Any step taken toward better security is a positive initiative but if the attack never reaches the user, it will be the best protection," Ang said. "Removing administrative rights may be one of the methods to improve security but it may not achieve the desired objectives."

Steinberg went on to point out that as enterprises move toward self-provisioning IT services, taking away administrative rights is "inappropriate" and for users to call on IT staff for permission to install software is "frustrating, inefficient and a waste of time".

Companies would be better off assessing the amount of user rights given depending on the job scope and work environment they are in, he suggested. For instance, in a highly sensitive workplace, administrative rights might be stripped as security is paramount and users should not be able to install any software, regardless of how frustrated they become, the CEO stated.

Ang agreed, adding that security policies have always been based on the concept of granting minimal privileges that are enough to complete one's role in the organization, and this will determine how much administrator privileges an employee is entitled to.

For companies in the midst of migrating to Windows 7, Yoshizawa reckoned that this is a good time to remove users' admin rights and, at the same time, train them on security aspects, including access control and tips to avoid malware. This would minimize user complaints and increase their awareness of compliance issues, he added.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Alibaba seeks $2.3B from shareholders for Yahoo deal http://t.co/ySyCwLvJ via @zdnetasia

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/L4QzDq3H

Kodak loses patent ruling against Apple, RIM - ZDNet Asia http://t.co/O7P8U2Ya

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia http://t.co/WJCfhWLs

Kodak loses patent ruling against Apple, RIM. http://t.co/N1j7aZ6o

#radio Radio Serbia by EnjoyIT 1.0 http://t.co/nGQFvX2E

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

2 hours ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate