Four signs your security program has gone too far
Our columnist suggests when it might be time to dial back a bit
June 24, 2008 12:00 PM ETMore columns
- Four signs your security program has gone too far
- Where are those infosec jobs?
- Security ahead of risk at the border
- A spring column cleaning
- Phishing in the backyard
- Four good reasons for Security to talk to HR
- Not where you think they are
- When disaster recovery's down to you
- At the airport, an ID theft takes flight
- Goodbye to the Year of the Fire Pig
- Mixing open- and closed-source, managing risk
- Privacy and piracy: What are we telling the kids?
Computerworld - When risk is present it calls for treatment, and security is a never-ending process ... right? Yes, but as a security professional, it's easy to become focused on the hard problems (download PDF) of security -- falling into the arms race for more, more, more security controls -- and lose sight of the impact of the controls themselves.
Balance is key in the push-pull between security and business objectives, and sometimes we on the security side go too far. (After all, the most truly secure computer is one that's unplugged, boxed up and dropped down a deep well. And sometimes that's tempting.) Here are some ideas for recognizing and pulling back from the edge when security controls or processes become unreasonable.
Locked out
A friend of mine was recently hired as information security manager at a major state agency. When I met him for lunch a month after he started, he was still sporting a stick-on visitor badge that indicated he needed an escort within the secure areas of his building. Likewise, I saw an international client's new help desk coordinator repeatedly locked out of her shared office when co-workers departed for a smoke break. Both of these people have significant levels of access to sensitive data, but end up locked out of their own workspaces -- physically as well as virtually -- because the identification and access management methods are overwrought or out of sync with the employment process.
The lack of coordination between issuance of physical and logical access indicates both problems in the hiring process and disjointed management decisions regarding access. I haven't seen many instances where new employees in any organization are greeted on their first day with a coordinated issuance of access credentials, computer, phone and keys. It's a challenge for most to simply get an ID badge on the first day.
A handy solution is to use the list of things that have to be done when someone is terminated. Human resources usually has a termination checklist (download PDF) of tasks that includes obtaining the employee's ID and keys; disabling system, network and application accounts; and ensuring that computers, mobile phone and other company property are returned. If one takes this list or another example and turns it around as a guideline for the access- and asset-granting process when a new employee is hired, it's easy to see where the delays and other problems might lie. The same people that authorize revocation of access upon termination ought to be the ones who grant it to begin with. If authorization from more than two or three people is required to make it all the way through the list, some streamlining is in order.
jon espenschied
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
Learn how you can meet the detailed technical requirements of HIPAA and delivers continuous compliance.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Confidently Meet Compliance Requirements
Download this Resource Now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Getting in Compliance with Government Data Regulations
Learn about various regulations and how to comply with them when you read this white paper from VeriSign.
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Maximizing Site Visitor Trust Using Extended Validation SSL
Provide site visitors visual cues that indicate your site is legitimate with Extended Validation (EV) SSL available from VeriSign.
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
Authentication as a Service by Forrester Research
Learn more about Authentication-as-a-Service today!
The Commercialization of ITIL: Lessons Learned
Register for this event today!
