It’s a truism, usually credited to the activities of the French military in the years between World Wars I & II, that generals were always fighting the last war. In the past ten years we’ve seen that a corollary could be added: the TSA is always trying to stop the last bomber. If this truism holds, then the Wikileaks activity could be a boon for the Identity and Access Management industry.
What’s up with encryption?
As my Network World colleague Scott Bradner noted in his column last week: “…it looks like the system is set up to permit low-level people wide access to millions of classified documents without a way to monitor such access, and the system permitted bulk download of these documents.”
It’s alleged that all of the documents Wikileaks published – hundreds of thousands of pages of data about the Iraq and Afghan wars and diplomatic postings from around the world – were leaked by Private Bradley Manning, who joined the US Army in 2007 and was posted to Baghdad, where he worked on classified army networks. Manning, known as a “geek” to those who know him, appears to have been able to access all but the most highly classified documents throughout the US defense and diplomatic networks.
Was nothing encrypted? Were there any Privileged User controls in place?
Evidently not.
My friend Maarten Stultjens (he’s a director of bHOLD) mentioned that unstructured data (such as diplomatic cables) is usually not considered important. He said: “In the many conversations I have with security managers few recognize the importance of this unstructured information. I keep hearing all important information is in SAP or Oracle and these systems are well under control. WikiLeaks will trigger a shift of attention to managing access to unstructured information: business plans, personnel files, notes from management meetings, vendor proposals for company’s investments etcetera. A very strong call for action to control access on file systems will be heard.”
In a rumor that Agreon’s Brian Brannigan heard, over 2 million people had access to the data that Pvt. Manning allegedly pilfered.
Confidential data, no matter how it’s stored or transmitted, should be encrypted at all times. Priveleged Users – those with access to confidential data – should be managed, monitored and audited at all times. This isn’t rocket science, it isn’t even cutting edge tech – it’s standard controls we’ve had available for many years.
It’s time to re-examine your own access governance and data governance policies, I think. Unless, of course, you want your confidential memos to appear on the front page of the New York Times.




