* Is IT responsible for end-user behavior?
The topic of IT nightmares spawned a discussion around IT responsibility in which network professionals have argued that while end-user behavior can put an environment at risk, proper technological and educational measures taken by IT could reduce the impact of such risk.
When a well-respected publication shared hacker tips, some in the IT industry felt it had gone too far. Others found the publishing of such security-sensitive information irresponsible, while others pointed out that the information shared in that particular article is freely available in many places. And readers of this newsletter said that IT needs to educate and train its end users to not engage in behaviors that put the company and themselves at risk. In addition, they also said that IT needs to make smart technology purchases, backed up with strong, enforceable policies, to make sure those that aren’t following suit aren’t posing a threat.
One reader shared the following thoughts:
“Regarding your statement of ‘IT managers don’t have it that easy,’ I would agree wholeheartedly. I was an IT manager for a small company and had quite a challenge. While large companies such as a GE, Microsoft, or Lockheed may have a large IT department (in-house or outsourced, small companies do not and they comprise a very large part of our economy, as I have so frequently read. Yet because of the intricate interwoven nature of business and technology’s part in the meshing, a security issue with a small company can affect a wide swath of big and small.
The WSJ article to which you refer does seem a foolish act as does the irresponsible release of any information about vulnerabilities in our technology. Yet when software (and hardware) developers and manufacturers refuse to remove these vulnerabilities, the liability produced is the basis of the IT manager’s nightmare. I would argue that, without the information, the IT manager cannot close those holes or lessen those risks, and they just don’t magically go away. Thus, given the publicizing of such information, the real nightmare lies with the IT manager who does nothing. Lastly, that people attempt to circumvent security controls speaks to two possible conditions: ignorance, in that they do not understand the risks to the business and their own livelihood, or malice, in that they are doing so to harm the company.
The former is easily rectified: training and keeping employees informed about the business, risks to it, and the consequence of ignoring those risks. As for the latter, well, I believe the only option is indeed knowing about and removing the vulnerability.
I am a very firm believer in education, in all of its aspects, and find that the need for more training and education of the workforce is mentioned frequently in the news as a strategic necessity for our country and to business. To rein in information for fear it will be misused means someone is not able to contribute to a business, our economy, our country, whatever, as they should–and that’s a terrible limitation.
And another reader agrees that responsible IT management could prevent some nightmares:
“We’ve got to accept more responsibility, and get real about what employees need to do their jobs. The WSJ article gives me cold shivers, too, more because of its ‘your IT department is the enemy’ mentality than about its suggestions, most of which anyone reading the WSJ will have already discovered on their own.
Companies *do* have the option of setting up secure remote access for their networks, but someone in management has to be willing to say “yes, our workers need this *and* we can’t keep pushing implementation of it to the back of the budget queue as we’ve done since 1998 instead of saying ‘we have bigger IT funding priorities so we’ll just forbid it to the users.’ How many of the scandals concerning client information that has been compromised on laptops have been the result of a lack of secure remote access to files and programs? Probably most of them. Why doesn’t anyone stop to ask *why* that VA employee or credit card company employee was running around with thousands of records of sensitive data on his/her machine?
Employees with secure remote access don’t need to do half the things in that article. (In case you’re thinking, ‘Gee, she must work for a secure remote access solutions provider.’ No, I’ve been working on contract for two large federal agencies for the past 10 years watching this unfold.)”




