IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Fri, Apr 25, 2008 17:58 EDT

Taking the Offensive with Insider Threats – How Financial Institutions Can Improve Risk Management

Topic: Infrastructure

Current Rating: 1 Comments: 0

The slowing economy and building mortgage crisis are major factors behind layoffs at well-known financial institutions like Bank of America, and the jolting acquisition of once-high-flying Bear Stearns by JPMorgan. With even the most optimistic economists predicting that these disruptions will continue into 2009 and mounting evidence that the vast majority of insider threat originates from disgruntled employees, controlling access to sensitive data has become an imperative.

Increasingly, organizations must shift their technology focuses away from ensuring users “can” get access to appropriate data and resources, to determining whether certain users “should” have access.
Immediately rescinding access to corporate systems and applications is also critical to avoiding costly, public data breaches. Sounds like it should be standard procedure, but the increased prevalence of insider breaches suggest otherwise. Many organizations have either failed to realize the risks of orphaned accounts and segregation of duties (SoD) violations, or do not have the security infrastructure in place to deal with them in a timely manner.

In an acquisition scenario, companies like JPMorgan must ensure a seamless transition for new employees, making sure they have appropriate access to the systems they need to continue doing their jobs, without negatively impacting customers. As a result of these prominent industry events, many organizations are left with questions like: How can we achieve long-term compliance in light of our turbulent business environments? How can we prevent vulnerabilities by removing privileged access from former employees, while maintaining access for those who still require it? Following are select best practices that provide practical advice for IT organizations seeking to implement a more productive, offensive approach to risk management:

1: Establish a Framework for Success
In order to address prominent audit and compliance concerns, many organizations turn to Identity and Access Management (IAM) solutions as a reliable framework for controlling access. If you do not currently have an IAM solution in place, establish a vision and supporting roadmap, but avoid trying to accomplish everything in one phase. I’ve yet to see evidence that this has ever succeeded. What you are really about to automate are detailed business processes for staff on-boarding, change, termination and periodic review. These processes are dependent on business, security and operations policies that will vary by business, location and even management level.

A more natural approach in defining a program around a vision or broad goals for efficiency and control is to begin with concrete projects that support these goals. If you do some quick analysis, you’ll find the pain points. In a retail bank, it might be hiring and firing tellers because the turnover rate is 100 percent annually, but in an insurance company turnover is typically very low. For them, it might be getting the independent brokers to periodically review access rights of everyone in their offices and assert that their access is reasonable and appropriate. For each different industry there are also different compliance regulations to think about.

Remember, incremental progress is better than delayed or unattainable perfection.

2: Build an Identity Roadmap
Any business school will tell you that you can’t manage what you can’t see – and this holds true for user identities.

If you don’t have a current map of who has access to what, then how can you respond to basic questions for the auditors? How do you know if people are over-credentialed? How do you disable their access when they leave? How do you even help them when they call the service desk?

Building this map can be difficult

You do not have flash or javascript support.
Average (1 vote)
1
 
Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 96 of IT's most insightful thinkers.

advertisement

  PARTNERS       PODCASTS       WEBCASTS    
 

From Laggard to Leader: Transforming the Data Center

This webcast offers an understanding of how customers are transforming their data centers, the successes and challenges of each approach, and how IT can become the driver to provide real business value and competitive advantage.

Sponsored by HP  Register for this Webcast »

 

Raising the Bar on Business Service Delivery

Applications drive every business, but as networks become more complex and dynamic, performance has become a key tenant in service delivery. In this CIO webcast, Forrester and Fluke Networks offer advice and best practices for ensuring high delivery with better application performance.

Sponsored by Fluke  Watch this webcast. »

 

The Universal Wireless Client

Learn how replacing multiple wireless clients with one Universal Wireless Client can cut support and help desk costs, increase end user satisfaction, improve security, and help implement Network Access Control.

Sponsored by Fiberlink  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

NAC launch from HP Procurve Podcast with Lippis Report, Part 1

ProCurve Networking by HP joins the Lippis Report to announce major product and organizational additions to their ProActive Defense strategy.  Read More »

 

Accenture's View on Web 2.0 and its impact on business

Publisher at CIO magazine, Bob Melk, talks to Accenture's Blair Jones about the emergence of Web 2.0...  Read More »

 

A Best-Practice Framework for Virtualization

This podcast offers insights and perspective on the various issues that relate to virtualization...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

CIO Viewpoints on Exchange 2007 Risks and Mitigation Strategies

Knowing where your peers have found limits and workarounds in areas including high availability, archiving, recovery, compliance, e-Discovery and storage growth can be essential in planning your successful Exchange 2007 migration.  Read More »

 

Find out what Forrester says about mobile endpoint security and its management.

Mobility raises productivity. But IT departments are hard-pressed to protect mobile data and to manage security software, wireless clients and regulatory compliance for mobile workers...   Read More »

 

Get Forrester's take on simplifying mobility with the universal wireless client.

Mobile workers want to use all types of wireless networks: WiFi, 3G cellular networks, corporate WLANs and home wireless networks. But how can IT support...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Build up or Tear down? See how UC makes sense with Nortel. Calculate your UC ROI

Predict the future with HP Insight Power Manager

Drive Business Value with Enterprise Social Computing - whitepaper

See how IBM helped Bharti create a new business model

Read how IBM helped Hughes enhance security

HP LaserJet M3035 MFP series starting at $1,599. » SHOP NOW. www.hp.com

NEW HP Color LaserJet CM3530n MFP starting at $2,499. » SHOP NOW. www.hp.com

Affordable technology-no compromise. HP server solutions

Make IT Work As One@novell.com

Learn about the software-based VoIP solution from Microsoft

CIO Starter Kit includes useful resources created by top CIOs. Free Download>>

Rolling the dice with your security? Take the Self-Assessment Test now

Request a Novell/Microsoft deployment workshop and kit

Request a Novell/Microsoft deployment kit

Compuware.com - See how we make IT rock around the world

SOA Educational Library at the TIBCO SOA Resource Center

A fresh look at the impact of customer intimacy.

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Learn how to leverage virtualization for a 74% savings in TCO.

Find out how you can affordably consolidate applications with VMware.

ESG Research on Server and Storage Virtualization

Webcast: Mitigate Operational Risk- Real Answers for Tough Times

Laptop Security: Where Do CIOs See Weaknesses?

How RFID Improves Data Center Efficiency

Paving the Way for Trusted Collaboration

SAS a Leader in Forrester BI report. Click here to see evaluation.

Protect data-HP All-in-One and Disk-Based systems

Microsoft SQL Server 2008. Read Case Studies, Watch Demos, & Download for Free

The 2008 CEO Study: Implications for the CIO

HP LaserJet P4014n printer starting at $799 after $100 IS. www.hp.com

NEW HP Color LaserJet CP3525n printer starting at $699. » SHOP NOW. www.hp.com

Predict the future with HP Insight Power Manager

A new level of interoperability. Make IT Work As One@novell.com

Businesses Transform with VMware Virtualization

IT Service Management: Metrics That Matter

Download the free CIO Starter Kit to access useful resources created by top CIOs

Log onto Hitachi True Stories, films inspired by the next great achievement

Request a Novell/Microsoft deployment workshop

Strong Authentication. Secure USB data storage. One Device

Discover PMI's credentials and career path tools

Learn how companies are changing how they reach out to their most profitable customers.

Discover what you need to consider when evaluating virtualization.

Webcast: SOA Brings Backend Systems into the Future, Rapidly & Successfully

Find out why IDC thinks virtualization is changing operating environments.

Explore the impact virtualization can have on your bottom-line.

Save with 0% Lease Offer on HP Servers and Storage

The Customer Communications Management Platform - Key Functionality and Best Practices

Data Center ROI with RFID Asset Tracking

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Get help navigating the management challenges of virtualization.