7 Security Rules Employees Love to Break

Opinion
Dec 7, 20071 min

Just spotted this one over on CSOonline.com — from a survey of 893 corporate IT workers, done by the Ponemon Institute:

1. Copying confidential information onto a USB memory stick: 87% of respondents believe their company’s policy forbids it, yet 51% they do it anyway. 2. Accessing web-based e-mail accounts from a workplace computer: 45% of those surveyed use webmail at work; 74% say there is no stated policy that forbids it. 3. Losing a portable data-bearing device: 39% of respondents say they have lost or misplaced such a device, and 72% of them did not report the lost device immediately. 4. Downloading personal software onto a company computer: 60% of respondents say there is no stated policy that forbids downloading personal software, a practice that 45% of respondents admit to. 5. Sending workplace documents as an attachment in e-mail: 33% of respondents send work documents as attachments, and 48% aren’t even sure whether or not that violates policy. 6. Disabling security and firewall settings: 80% of those surveyed don’t know whether disabling security is against policy; 17% of respondents do it. 7. Sharing passwords with co-workers: 67% say the company’s policy forbids sharing passwords, but 46% of them do it anyway.