- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
![]() |
Here's a nasty little truth about the data-leakage problem: The people charged with keeping information systems up and running often pose the biggest threat to information protection. They've got broad access and powerful tools, and they know how to circumvent typical content-protection mechanisms.
This reality has some IT executives exploring ways to tighten up operational processes. Tom Ferris, a senior IT officer for an international financial organization in Washington, D.C., is ditching a traditional server-administration model for one that strictly limits access by role. For example, application developers no longer get full administrative access to and control of all servers. Now they have access to test and development servers but not the production environment, Ferris says. Additionally, for maintenance purposes he uses BladeLogic's data-center automation software to set role-based access controls and limit the types of tasks allowed.
Is IT your biggest threat? Place a vote and share your opinions.
Kern Weissman, director of network systems at Velocity Express, a same-day package-delivery company in Westport, Conn., also is narrowing administrative access to servers. "Instead of saying, 'You have access to this system for this amount of time,' we'll say, 'You have access to this system and this application for this amount of time,'" he says.
The company will gain this control through Xceedium's GateKeeper, which lets remote administrators manage centralized servers securely. GateKeeper consolidates access with a Web portal, through which all administrators must pass to gain systems access. Everything is encrypted, including the tools available through applets on the portal, and a company need only open one firewall port, says Cheryl Traverse, Xceedium CEO. Even rebooting failed machines is handled through the portal, because GateKeeper consolidates network access, out-of-band signaling and power on a single connection.
Martin O'Reilly, IT director at the Rutgers School of Business in Camden, N.J., considers GateKeeper a security tool. "We use it as the sole access point to our mission-critical systems," he says. An administrator has an access account on the Web portal, and the mission-critical system will allow access only from the GateKeeper connection, he adds. "When I think about the insider threat, I think about the misuse of applications or systems that render them insecure," O'Reilly says. "And this certainly provides another [protection] layer - and, of course, that's the ultimate goal."
If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comments (1)
gatekeeper(s)By tuomoks on April 10, 2008, 2:30 pmA good idea but this level access control is ages old, IT (and other) threats is nothing new. Now, the implementations have been very few. technology thinking took...
Reply | Read entire comment
View all comments