Contributor

Baby sitting IT security admins. Five questions the City of San Francisco should have asked.

Opinion
Jul 21, 20081 min

San Fran City Hall

The ongoing Terry Childs fiasco within the city government of San Francisco could have been easily avoided. Thanks to Chad Perrin for his excellent summary of the story.  As things stand the city is not able to update, change, or manage their WAN because they have had the only person who knows the admin passwords arrested and retained on a $5 million bond.  

Read Chad’s post for the details.  My advice is for every business owner and government administration to immediately check on the controls of their IT infrastructure. Ask yourself these questions:

1. Do you have centralized authentication and rights management?

2. Are passwords on infrastructure devices and applications routinely changed?

3. Who are the key individuals in your security hierarchy?  Have you exposed yourself to unacceptable risk levels by granting them too high a level of trust?

4. Do you do background checks on new hires?

5. Do you have a written policy governing administrative passwords and rights management?

The answers to these questions are going to give you your task list for the remaining weeks of the summer. Get your access control system under control before you face the same embarrassment the City of San Francisco is suffering.   

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author