Alibaba seeks $2.3B from shareholders for Yahoo deal http://t.co/ySyCwLvJ via @zdnetasia
27 minutes ago by arbastaki on twitterZDNet is available in the following editions:
Disallowing admin rights of employees' endpoint devices not realistic solution to preventing malware threats in today's self-service IT business climate, observers say.
tatsuya yoshizawa, joseph steinberg, science and technology, computer technology, software, technology, neil macdonald, computer security, spyware and adware, viruses and worms
The removal of administrative rights to employees' endpoint devices such as desktops and laptops is not a foolproof security solution and unrealistic in today's era of IT consumerization. Rather, risk assessment of employees' job scope to determine level of admin rights given and training are more feasible options, industry insiders argued.
Tatsuya Yoshizawa, product marketing manager of Blue Coat Systems, said removing administrative rights to devices for workers may seem counter-intuitive but it is one of the more "reasonable" solutions to protect the company's data from external threats. Such a move will make endpoint security more secure and eliminates the risk of users unknowingly downloading and installing malware, he added.
That said, the Japan-based executive noted that the removal of such rights does not mean that IT administrators can stop users from accessing malicious or inappropriate Web sites or control specific operations within an application. Actions include uploading sensitive documents on a public forum or sending a customer list via their private Web e-mail clients, he explained.
Besides, for large enterprises, revoking admin rights for all employees in order to boost security could turn into a time- and labor-intensive initiative, Yoshizawa noted.
Joseph Steinberg, CEO of New Jersey-based Green Armor Solutions, chimed in, saying that even by taking away users' admin rights, plenty of problems--including malware--can still arise, he said during a phone interview.
Both of them were responding to a blog post written last month by Neil Macdonald, vice president and distinguished analyst at Gartner, in which he argued that for enterprises thinking of switching security vendors because of "malware infestations" challenges, they should first look at the option of removing administrator rights for users' endpoint devices.
MacDonald also mentioned in a blog post this May that removing administrative rights for Window users is not a "lockdown", as users can still install and execute well-written software, printer drivers, ActiveX controls and standard day-to-day Windows functions such as changing time zones or monitor resolution.
Consider business environments, security policies
While Windows-based systems may be more easily controlled through such domain policies, Ang Chye Hin, regional director of SonicWALL Southeast Asia, pointed out that other platforms will require another set of controls that may be an "unnecessary burden" for organizations with less available resources.
It will also be challenging if the organization does not have an established security management framework that covers the objectives of the organization's security strategy, rules and policies, he added. This framework would look into what rights should be removed or granted, exceptions to the rule and developing user awareness programs, he explained.
"Any step taken toward better security is a positive initiative but if the attack never reaches the user, it will be the best protection," Ang said. "Removing administrative rights may be one of the methods to improve security but it may not achieve the desired objectives."
Steinberg went on to point out that as enterprises move toward self-provisioning IT services, taking away administrative rights is "inappropriate" and for users to call on IT staff for permission to install software is "frustrating, inefficient and a waste of time".
Companies would be better off assessing the amount of user rights given depending on the job scope and work environment they are in, he suggested. For instance, in a highly sensitive workplace, administrative rights might be stripped as security is paramount and users should not be able to install any software, regardless of how frustrated they become, the CEO stated.
Ang agreed, adding that security policies have always been based on the concept of granting minimal privileges that are enough to complete one's role in the organization, and this will determine how much administrator privileges an employee is entitled to.
For companies in the midst of migrating to Windows 7, Yoshizawa reckoned that this is a good time to remove users' admin rights and, at the same time, train them on security aspects, including access control and tips to avoid malware. This would minimize user complaints and increase their awareness of compliance issues, he added.
Alibaba seeks $2.3B from shareholders for Yahoo deal http://t.co/ySyCwLvJ via @zdnetasia
27 minutes ago by arbastaki on twitterRise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/L4QzDq3H
57 minutes ago by LocalMobile911 on twitterKodak loses patent ruling against Apple, RIM - ZDNet Asia http://t.co/O7P8U2Ya
57 minutes ago by PatentWire on twitterRise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia http://t.co/WJCfhWLs
57 minutes ago by JapanTechnology on twitterKodak loses patent ruling against Apple, RIM. http://t.co/N1j7aZ6o
1 hour ago by zdnetasia on twitterRise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR
1 hour ago by GeorgeHAllenGA on twitterRise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c
1 hour ago by MergeAcquire on twitterRT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb
2 hours ago by 666hellscream on twitterCFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX
2 hours ago by HarishAitharaju on twitterRise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o
2 hours ago by zdnetasia on twitterRT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o
2 hours ago by wrikent3500 on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
2 hours ago by y15822137359 on 5 SaaS adoption speed bumps to avoidRise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL
2 hours ago by MandAWorldwide on twitterRise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir
2 hours ago by V_RaV on twitterhttp://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt
2 hours ago by RavtachSolution on twitterI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
3 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
4 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.