Archive for the ‘Insider Abuse’ Category

“Ten Things Your IT Department Will Not Tell You” (and That They Should Block)

Saturday, August 4th, 2007

I read an intriguing article today about “Ten Things Your IT Department Will Not Tell You.” The “Ten Things” were basically methods for circumventing security policies in a corporate network. In a lot of cases, no harm is done if you bend a few rules for legitimate reasons and use good security practices (e.g. securely uploading files to a web server so that you can work at home). However, the article completely failed to mention that the reason a lot of these policies are in place is not to hamper an overly ambitious worker, but to prevent information theft from malicious insiders, which is a very serious threat. (more…)