Feeds

iPhones and social networking add to IT security headaches

A security admin's life is not a happy one

Combat fraud and increase customer satisfaction

RSA Europe 2009 The flood of consumer devices such as iPhones into the enterprise and workers giving away snippets of potential sensitive information via social networking sites have emerged as new threats in the information security landscape.

During a roundtable at the RSA Conference Europe 2009, in London, Herbert Thompson, chief security strategist at People Security, explained how snippets of information that might by themselves appear unimportant can be put together like a jigsaw to reveal potentially sensitive information. For example, a series of new LinkedIn recommendations referring to senior staff at a single company could be a sign of an imminent merger.

Alternatively it could suggest that workers at an organisation of interest are searching for jobs. “The data seems harmless but when you correlate it across a group of people it can become interesting,” Thompson explained. The risk adds to the better understood problem of individuals giving away potentially sensitive personal information, such as a time when they are away on holiday, via social networking sites such as Twitter. Micro blogging also poses a means for organizations to leak potentially sensitive morsels of information.

For example, if someone with a sales job says that they are flying to Bentonville for work it’s a fair bet that they are traveling to the headquarters of Wall-Mart since there’s little else in the town.

Data loss prevention is touted as a means of guarding against the leak of confidential information but “it’s no use to apply DLP technology without first classifying data”, explained John Madelin, head of professional services at Verizon Business. Educating users about the potential pitfalls of social networking is the best way of tackling the problem, he added.

Mobile devices in the enterprise pose another challenge but adopting security policies to control how smartphones such as the iPhone are used by enterprise users is rarely successful. Newer mobile technology is more stylish and fashionable than anything a corporation might supply.

Furthermore, firms are under cost pressure to allow workers to bring in their own devices.

Information security staff face more traditional threats alongside the new risks in areas such as application security. Web applications, in particular, remain a frequent source of security problems because developers are pushed to implement new features but not encouraged to think about security in writing new apps. “Security runs counter to usability, Thompson explained. “There’s also a trade-off between performance and security,” he added. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.